Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   svchost.exe greift auf clickhosterseiten zu (im hintergrund) (https://www.trojaner-board.de/165405-svchost-exe-greift-clickhosterseiten-hintergrund.html)

Friedrich_ 23.03.2015 09:07

svchost.exe greift auf clickhosterseiten zu (im hintergrund)
 
Liste der Anhänge anzeigen (Anzahl: 2)
Hallo Gemeinde,

Mir ist seit einigen Tagen ungewöhnlicher Traffic in meinen Logs aufgefallen die von meinem System ausgehen.
Dies passiert direkt nach dem Systemstart und zieht sich fort. (Es ist nur der PC im LAN Online)
Wenn die LAN-Verbindung deaktiviert ist, zeigen sich auch keine auffälligkeiten. Logisch.
Es wird auch kein Fenster/Werbung etc. geöffnet wenn die Kontaktversuche stattfinden! Was ich noch
beobachten konnte, Seitdem hängt sich auch die komplette taskleiste manchmal für ein paar minuten auf.(aber nicht zu dem genauen Zeitpunkt wo der Verkehr stattfindet).


Caches werden täglich mehrmals nach jedem Browserschließen mit ClearProg, und zusätzlich mit CCleaner bereinigt.
Flash und Java jeweils auf dem neuesten Stand (tägliche manuelle Prüfung auf updates).
Windows/Office Updates jeweils auf aktuellstem Stand, sowie Definitionsfiles entsprechender programme.

Was noch Wichtig ist, ist, das diese Clickjackerseiten im Diagnosestart/Abgesicherter Modus nicht aufgerufen werden,
trotz internetverbindung/nutzung! Das passiert nur im normalen Startmodus.
Zudem öffnet sich auch kein Browser oder derartiges. Mir ist der Traffic lediglich über die Netzwerktools sowie auch Wireshark aufgefallen.

Ich hab vorweg schon mal Combofix ausgeführt. Bedauerlicherweise hatte mir Combofix
die hosts geleert welche ich z.G. wiederherstellen konnte (und dort fleißig diese clickjackerseiten auf localhost nachtrage),
Und noch ein paar weitere files unteranderem Screenshots, eigens angefertigte harmlose logs.. usw.
Mein Hauptbrowser, der Firefox ist gründlich abgeriegelt, Kein Caching, Keine Cookies, NoScript, DoNotTrack sowie Ghostery und einige andere erweiterungen.
Mir wird dort und in den anderen Browsern auch keine Werbung angezeigt, oder das es diese seiten jemals im browser geöffnet hatte. Da war nichts.
Den Firefox mit seinen Erweiterungen können wir ausschließen, da ich diesen als exaktes Abbild auf meinen anderen 3 rechnern auch nutze.

Ich Hoffe das wir das problem gemeinsam identifizieren können und lösen, gerne Spende ich dann auch einen kleinen Betrag an euch, wenn wir den Übeltäter beseitigen können!

PS: Es ist im Grunde ein sehr gepflegtes und sauberes, ruckelfreies System, Bis jetzt auf den Vorfall.

System:
i7-3770 auf Windows 7 32bit.

bereits Durchgeführte Scan's
Code:

PandaSafe LiveCD -Keine funde
Bitdefender LiveCD -Keine funde

Malwarebytes Anti Malware -Keine funde
Malwarebytes Anti-Rootkit -Keine funde
Spybot Search&Destroy -Keine funde
Spyware Terminator 2012 -Keine funde
Microsoft Security Scanner -Keine funde
Zone Alarm Antivirus Extreme -Keine funde
ClamWin Antivirus -Keine funde
TrendMicro RUBotted -Keine Auffälligkeiten
TrendMicro OnlineScanner -Keine deartigen Funde
Detekt -Keine funde
TDDSKiller -Keine funde
BitDefender BootkitRemover -Keine funde
AVG Virus Remover for Bootkit -Keine funde
McAfee Stinger -Keine funde

Übersicht mittels Screenshots als anhang.

Und nun die Logs:

AdwCleaner-Log
Code:

# AdwCleaner v4.112 - Bericht erstellt 23/03/2015 um 03:01:35
# Aktualisiert 09/03/2015 von Xplode
# Datenbank : 2015-03-05.1 [Lokal]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x86)
# Benutzername : * - DSLSERVICE
# Gestarted von : C:\Users\Friedrich\Desktop\Sicherheitsprogramme\adwcleaner_4.112.exe
# Option : Suchlauf

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gefunden : C:\Users\*\AppData\Local\PackageAware
Ordner Gefunden : C:\Windows\Uninstaller

***** [ Geplante Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Daten Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>
Schlüssel Gefunden : HKCU\Software\Headlight
Schlüssel Gefunden : HKCU\Software\Mozilla\Extends
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A1CCCE0D-AE21-42A2-BE58-8E6109410995}
Schlüssel Gefunden : HKLM\SOFTWARE\Headlight
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\allSnap_is1
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sonic the Hedgehog 4 - Episode II (c) SEGA_is1
Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi

***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17689


-\\ Mozilla Firefox v36.0.4 (x86 de)

[bmct2hvv.default] - Zeile Gefunden : user_pref("extensions.quick_start.enable_search1", false);
[bmct2hvv.default] - Zeile Gefunden : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);

-\\ Chromium v

*************************

AdwCleaner[R0].txt - [2696 Bytes] - [05/07/2014 01:32:15]
AdwCleaner[R10].txt - [2972 Bytes] - [19/03/2015 05:08:27]
AdwCleaner[R11].txt - [3033 Bytes] - [19/03/2015 08:52:58]
AdwCleaner[R12].txt - [2906 Bytes] - [22/03/2015 22:42:07]
AdwCleaner[R13].txt - [1900 Bytes] - [23/03/2015 03:01:35]
AdwCleaner[R1].txt - [2108 Bytes] - [05/07/2014 01:44:43]
AdwCleaner[R2].txt - [2092 Bytes] - [05/07/2014 01:51:47]
AdwCleaner[R3].txt - [2152 Bytes] - [22/07/2014 16:45:56]
AdwCleaner[R4].txt - [2309 Bytes] - [27/08/2014 00:30:24]
AdwCleaner[R5].txt - [2646 Bytes] - [27/08/2014 15:45:37]
AdwCleaner[R6].txt - [2706 Bytes] - [27/08/2014 15:51:46]
AdwCleaner[R7].txt - [2858 Bytes] - [01/09/2014 18:35:30]
AdwCleaner[R8].txt - [2695 Bytes] - [20/12/2014 19:07:20]
AdwCleaner[R9].txt - [2912 Bytes] - [10/03/2015 19:00:19]
AdwCleaner[S0].txt - [2649 Bytes] - [05/07/2014 01:39:52]
AdwCleaner[S1].txt - [2061 Bytes] - [05/07/2014 01:48:59]
AdwCleaner[S2].txt - [2843 Bytes] - [19/03/2015 09:34:59]

########## EOF - C:\AdwCleaner\AdwCleaner[R13].txt - [2668 Bytes] ##########

Hijackthis-Log
Code:

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 05:41:47, on 23.03.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)

FIREFOX: 36.0.4 (x86 de)
Boot mode: Normal

Running processes:
C:\Program Files\EMET 5.1\EMET_Agent.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Virtual CD v10\System\VC10Play.exe
C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files\CheckPoint\AKL\AkSA.exe
C:\Program Files\Razer\Synapse\RzSynapse.exe
C:\Program Files\allSnap\allSnap.exe
C:\Windows\explorer.exe
C:\Users\Friedrich\Desktop\Sicherheitsprogramme\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll
O4 - HKLM\..\Run: [VC10Player] C:\Program Files\Virtual CD v10\System\VC10Play.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\AKL\AkSA.exe" /icon="hidden"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files\Razer\Synapse\RzSynapse.exe"
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [Trend Micro RUBotted V2.0 Beta] C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKCU\..\Run: [DMS-Kalenderchen] "C:\Program Files\Kalenderchen\Kalenderchen.exe" /autorun
O4 - Startup: allSnap.lnk = C:\Program Files\allSnap\allSnap.exe
O8 - Extra context menu item: Mit GetRight downloaden - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Mit Getright-Browser öffnen - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{540DE981-1465-410D-993D-5B1652998DCB}: NameServer = 192.168.44.44
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: DokanMounter - Unknown owner - C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe
O23 - Service: Futuremark SystemInfo Service - Futuremark - C:\Program Files\Futuremark\SystemInfo\FMSISvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ZoneAlarm AntiKeylogger IswSvc (IswSvc) - Check Point Software Technologies LTD - C:\Program Files\CheckPoint\AKL\AkSVC.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NetLimiter 3 NDIS driver (nlndis) - Locktime Software - C:\Program Files\NetLimiter Ndis Miniport Service\nlndis.exe
O23 - Service: NetLimiter 3 Service (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 3\nlsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: OpenVPN Service (OpenVPNService) - The OpenVPN Project - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files\Origin\OriginClientService.exe
O23 - Service: Realtek87B - Realtek - C:\Program Files\Realtek\RTL8187 Wireless LAN Utility\RtlService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Riverbed Technology, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Trend Micro RUBotted Service (RUBotSrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Virtual CD v10 Management Service (VC10SecS) - H+H Software GmbH - C:\Program Files\Virtual CD v10\System\VC10SecS.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: VMware Workstation Server (VMwareHostd) - Unknown owner - C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies Ltd. - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
O23 - Service: ZoneAlarm Privacy Service (ZAPrivacyService) - Check Point Software Technologies, Ltd. - C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
O23 - Service: ZoneAlarm AntiTheft - Check Point Software Technologies Ltd. - C:\Program Files\CheckPoint\AntiTheft\Antitheft.exe

--
End of file - 7380 bytes


Junkware Removal Tool-Log
Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.5 (03.17.2015:1)
OS: Windows 7 Professional x86
Ran by Friedrich on 23.03.2015 at  0:18:46,87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted: [Folder] C:\Users\Friedrich\AppData\Roaming\mozilla\firefox\profiles\bmct2hvv.default\extensions\{ef522540-89f5-46b9-b6fe-1829e2b572c6}
Successfully deleted the following from C:\Users\Friedrich\AppData\Roaming\mozilla\firefox\profiles\bmct2hvv.default\prefs.js

user_pref("extensions.customizegoogle.cookies.SafeSearch", false);
user_pref("extensions.customizegoogle.cookies.enableSafeSearch", false);



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.03.2015 at  0:22:09,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Ein GMER log konnte ich nicht posten, da es auch im AbgesichertenModus bei der Stelle wo die VolumeShadowCopy geprüft wird, sich beendet. Nach dem 3x hintereinander ausführen kommt dann ein Bluescreen bei besagter Volumen-Schattenkopie Stelle.

Einige Adressen auf die die svchost zugreift, eigtl immer die gleichen.
Code:

37.220.34.13 www.kesefkal.net

192.64.147.209 www.onlineearningcenter.com

192.64.147.209.voodoo.com       

                www.ruspromotion.net                                69.43.160.178
        host.bogiehosting.net                                       
redirector-sjl.enom.com                                       
67.18.22.5  www.megacashclicks.net
141.8.225.80 www.lionclix.com


www.hotrusclick.com 144.76.188.252
uniqwork.com  93.95.100.90


www.theadclick.com 208.73.210.200
www.stormpay.com 98.124.199.1
www.hybridtraffic.com 50.63.202.4

69.64.147.242 www.bulldogsclicks.com

Hostname        Methode        Pfad        User-Agent        Antwort-Code        Antwort-String        Inhaltsart        Internetadresse        Klientenadresse        Serveradresse        Herkunft        Inhaltscodierung        Übertragunscodierung        Server        Inhaltslänge        Verbindung        Cache-Steuerung        Standort        Serverzeit        Verfall        Letzte Aktualisierung        Cookie        Abfragezeit        Antwortszeit       
www.dpx-money.info        GET        /index.php?refid=7285er        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        200        OK        text/html        hxxp://www.dpx-money.info/index.php?refid=7285er        192.168.44.33:1035        94.23.11.202:80                        chunked        Apache/2.2.23 (Win32) PHP/5.3.27 mod_ssl/2.2.23 OpenSSL/0.9.8x        412        close                        22.03.2015 20:45:49                                00:00:11.372        49 ms       
www.egcash.com        GET        /index.php?refid=4839d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        200        OK        text/html; charset=UTF-8        hxxp://www.egcash.com/index.php?refid=4839d        192.168.44.33:1045        72.52.4.121:80                                Apache        20578        close        post-check=0, pre-check=0                22.03.2015 20:47:44        26.07.1997 05:00:00        22.03.2015 20:47:44                00:02:05.785        128 ms       
www.trafficdinar.com        GET        /signup.php?r=1296d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        200        OK        text/html; charset=UTF-8        hxxp://www.trafficdinar.com/signup.php?r=1296d        192.168.44.33:1050        72.52.4.119:80                                Apache        29288        close        post-check=0, pre-check=0                22.03.2015 20:48:21        26.07.1997 05:00:00        22.03.2015 20:48:21                00:02:42.914        31 ms       
www.kesefkal.net        GET        /ru/?refer=557837d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        301        Moved Permanently                hxxp://www.kesefkal.net/ru/?refer=557837d        192.168.44.33:1052        37.220.34.13:80                                Microsoft-IIS/7.5        0        close                hxxp://www.xn----miceskz.net:80/ru/?refer=557837d        22.03.2015 20:50:45                                00:05:16.832        38 ms       
www.ruspromotion.net        GET        /site/index.php?ref=73425d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        302        Found        text/html; charset=UTF-8        hxxp://www.ruspromotion.net/site/index.php?ref=73425d        192.168.44.33:1056        69.43.160.178:80                                Apache        0        close                hxxp://ww1.ruspromotion.net/site/index.php?ref=73425d        22.03.2015 20:51:32                                00:05:53.942        256 ms       
www.onlineearningcenter.com        GET        /members/63497d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        404        Not Found        text/html; charset=UTF-8        hxxp://www.onlineearningcenter.com/members/63497d        192.168.44.33:1063        192.64.147.209:80                                Apache/2.2.3 (CentOS)        1455        close        no-cache, no-store, must-revalidate, post-check=0, pre-check=0                22.03.2015 20:52:13        31.12.2001 07:32:00                        00:06:33.966        245 ms       
www.stormpay.com        GET        /?53867d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        302        Found        text/html        hxxp://www.stormpay.com/?53867d        192.168.44.33:1113        98.124.199.1:80                        chunked        Redirector/1.0        155        close        private        hxxp://127.0.0.1/53867d        22.03.2015 20:52:52                                00:07:11.179        189 ms       
www.theadclick.com        GET        /pages/index.php?refid=54530d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        200        OK        text/html; charset=UTF-8        hxxp://www.theadclick.com/pages/index.php?refid=54530d        192.168.44.33:1122        208.73.210.200:80                                Apache        946        Keep-Alive                        22.03.2015 20:53:26                                00:07:48.127        301 ms       
www.megacashclicks.net        GET        /index.php?ref=23486d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        404        Not Found        text/html; charset=iso-8859-1        hxxp://www.megacashclicks.net/index.php?ref=23486d        192.168.44.33:1151        67.18.22.5:80                                nginx        326        close                        22.03.2015 20:54:41                                00:09:02.259        220 ms       
www.lionclix.com        GET        /index.php?ref=54377d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        200        OK        text/html; charset=UTF-8        hxxp://www.lionclix.com/index.php?ref=54377d        192.168.44.33:1171        141.8.225.80:80                                Apache        894        Keep-Alive                        22.03.2015 20:55:18                                00:09:39.755        183 ms       
www.hotrusclick.com        GET        /signup.php?r=2783d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        200        OK        text/html        hxxp://www.hotrusclick.com/signup.php?r=2783d        192.168.44.33:1185        144.76.188.252:80                                Apache/2        6        close                        22.03.2015 20:54:40                                00:10:16.446        58 ms       
uniqwork.com        GET        /rjoin.asp?id=63488d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        302        Object moved        text/html        hxxp://uniqwork.com/rjoin.asp?id=63488d        192.168.44.33:1342        93.95.100.90:80                                Microsoft-IIS/6.0        129        close        private        d-ru.asp        22.03.2015 20:57:07                                00:11:29.324        192 ms       
www.egcash.com        GET        /index.php?refid=7285er        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        200        OK        text/html; charset=UTF-8        hxxp://www.egcash.com/index.php?refid=7285er        192.168.44.33:1644        72.52.4.121:80                                Apache        20579        close        post-check=0, pre-check=0                22.03.2015 20:58:23        26.07.1997 05:00:00        22.03.2015 20:58:23                00:12:44.419        53 ms       
www.hybridtraffic.com        GET        /index.php?ref=5534d        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        302        Found                hxxp://www.hybridtraffic.com/index.php?ref=5534d        192.168.44.33:1779        50.63.202.4:80                                        0        close        no-cache        /index.php?ref=5534d                                        00:13:21.772        189 ms       
www.bulldogsclicks.com        GET        /index.php?ref=7285er        Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0;1:0        200        OK        text/html; charset=utf-8        hxxp://www.bulldogsclicks.com/index.php?ref=7285er        192.168.44.33:1868        69.64.147.242:80                                Microsoft-IIS/7.5        7109        close        no-cache                22.03.2015 20:59:39                                00:13:58.592        152 ms

Die Browserkennung die er dabei verwendet ist immer die gleiche.
Mozilla/5.0 (Macintosh; 3c7; PPC Mac OS X; en-US) AppleWebKit/15e.5 (KHTML, like Geco, Safari) OmniWeb/vc12.de0
CPU-Auslastung gen 0%, keine anwendungen offen, alles geschlossen! Festplatte ruht.

mfg.

schrauber 23.03.2015 09:08

hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Friedrich_ 23.03.2015 09:15

re
 
Die FRST's hab ich bereits erstellt gehabt.

FRST-Log

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by Friedrich (administrator) on DSLSERVICE on 23-03-2015 05:28:41
Running from C:\Users\Friedrich\Desktop
Loaded Profiles: Friedrich (Available profiles: Friedrich)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
() C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe
(Microsoft Corporation) C:\Program Files\EMET 5.1\EMET_Service.exe
(O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
(H+H Software GmbH) C:\Program Files\Virtual CD v10\System\VC10SecS.exe
(VMware, Inc.) C:\Windows\System32\vmnat.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\AntiTheft\Antitheft.exe
(VMware, Inc.) C:\Windows\System32\vmnetdhcp.exe
(VMware, Inc.) C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\EMET 5.1\EMET_Agent.exe
(H+H Software GmbH) C:\Program Files\Virtual CD v10\System\VC10Play.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Check Point Software Technologies LTD) C:\Program Files\CheckPoint\AKL\AkSA.exe
(Razer Inc.) C:\Program Files\Razer\Synapse\RzSynapse.exe
(Ivan Heckman) C:\Program Files\allSnap\allSnap.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [VC10Player] => C:\Program Files\Virtual CD v10\System\VC10Play.exe [411976 2011-10-19] (H+H Software GmbH)
HKLM\...\Run: [USB3MON] => C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM\...\Run: [ISW] => C:\Program Files\CheckPoint\AKL\AkSA.exe [638584 2014-05-14] (Check Point Software Technologies LTD)
HKLM\...\Run: [LifeCam] => C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\Run: [Razer Synapse] => C:\Program Files\Razer\Synapse\RzSynapse.exe [590144 2015-02-28] (Razer Inc.)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [153672 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [Trend Micro RUBotted V2.0 Beta] => C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe [1102872 2013-07-25] (Trend Micro Inc.)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Run: [DMS-Kalenderchen] => C:\Program Files\Kalenderchen\Kalenderchen.exe [3498496 2010-05-18] (Daniel Manger Software)
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\allSnap.lnk
ShortcutTarget: allSnap.lnk -> C:\Program Files\allSnap\allSnap.exe (Ivan Heckman)
SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll (Stardock.net, Inc)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
BootExecute: autocheck autochk * OODBS

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-06] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-06] (Oracle Corporation)
Winsock: Catalog9 11 C:\Windows\system32\vsocklib.dll [63568] (VMware, Inc.)
Winsock: Catalog9 12 C:\Windows\system32\vsocklib.dll [63568] (VMware, Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{540DE981-1465-410D-993D-5B1652998DCB}: [NameServer] 192.168.44.44

FireFox:
========
FF ProfilePath: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default
FF NewTab:
FF Homepage: about:blank
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.http", "");
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.http_port", 0);
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.no_proxies_on", "");
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.share_proxy_settings", true);
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF NetworkProxy: "backup.ftp", "127.0.0.1"
FF NetworkProxy: "backup.ftp_port", 8080
FF NetworkProxy: "backup.gopher", "www-proxy.t-online.de"
FF NetworkProxy: "backup.gopher_port", 80
FF NetworkProxy: "backup.socks", "127.0.0.1"
FF NetworkProxy: "backup.socks_port", 8080
FF NetworkProxy: "backup.ssl", "127.0.0.1"
FF NetworkProxy: "backup.ssl_port", 8080
FF NetworkProxy: "ftp", "127.0.0.1"
FF NetworkProxy: "ftp_port", 8080
FF NetworkProxy: "gopher", "127.0.0.1"
FF NetworkProxy: "gopher_port", 4001
FF NetworkProxy: "http", "127.0.0.1"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "no_proxies_on", ""
FF NetworkProxy: "pong", ""
FF NetworkProxy: "pong_port", 0
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "127.0.0.1"
FF NetworkProxy: "socks_port", 8080
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "127.0.0.1"
FF NetworkProxy: "ssl_port", 8080
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-12] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll [2013-12-05] (Adobe Systems, Inc.)
FF Plugin: @checkpoint.com/FFApi -> C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll No File
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\PDF-XChange Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @esn/npbattlelog,version=2.4.0 -> C:\Program Files\Battlelog Web Plugins\2.4.0\npbattlelog.dll [2014-05-26] (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-06] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-06] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @nullsoft.com/winampDetector;version=1 -> C:\Program Files\Winamp Detect\npwachk.dll [2013-12-13] (Nullsoft, Inc.)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\PDF-XChange Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin HKU\S-1-5-21-3642466463-2128021046-2334674927-1002: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\PDF-XChange Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-3642466463-2128021046-2334674927-1002: eyes.nasa.gov/NASAEyes -> C:\Users\Friedrich\AppData\Roaming\JPLNASAVTAD\NASAEyes\1.0.0.0\npNASAEyes.dll [2013-08-02] (JPL/NASA-Caltech)
FF Plugin HKU\S-1-5-21-3642466463-2128021046-2334674927-1002: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Trials Evolution Gold Edition\datapack\orbit\npuplaypc.dll [2013-03-18] (Ubisoft)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-03-06] (Apple Inc.)
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\a9.xml [2013-06-01]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\blekko-https.xml [2015-03-18]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\blekko.xml [2015-03-18]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\duckduckgo.xml [2012-07-03]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\expediadotcom.xml [2007-03-08]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\flickr-tags.xml [2013-07-08]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\geizhalseu.xml [2015-03-02]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\geo-ip-tool.xml [2014-10-04]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\gutscheinrauschde-suche.xml [2011-03-22]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\hollywoodcom.xml [2013-10-05]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\imdb.xml [2008-10-22]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\ixquick-ssl.xml [2014-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\lycos-europe.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\MSN.xml [2013-10-05]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\neckermannde.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\otto.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\qwantcom.xml [2014-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\spinde.xml [2009-03-16]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\t-online.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\weathercom.xml [2015-03-18]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\wolframalpha.xml [2014-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\youtube-videosuche.xml [2015-03-19]
FF Extension: Cache Status - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\cache@status.org [2014-05-03]
FF Extension: Chromifox Basic - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\chromifox@altmusictv.com [2013-01-29]
FF Extension: Blur (Formerly DoNotTrackMe) - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\donottrackplus@abine.com [2014-11-22]
FF Extension: FoxyProxy Standard - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\foxyproxy@eric.h.jung [2015-03-22]
FF Extension: HTTPS-Everywhere - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\https-everywhere@eff.org [2015-01-23]
FF Extension: GutscheinRausch.de - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\jl@leimbach-it.de [2013-01-29]
FF Extension: rein - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\rein@notiz.jp [2013-04-30]
FF Extension: TinEye Reverse Image Search - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\tineye@ideeinc.com [2013-01-29]
FF Extension: Forecastfox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013-01-29]
FF Extension: Elementary - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{05e38d80-09c1-11dd-bd0b-0800200c9a66} [2013-01-29]
FF Extension: Vista-aero - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{07b2a769-ed19-4483-87ce-c643914c81bb} [2013-01-29]
FF Extension: PONG! - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1368F36C-0370-419a-A408-28F94FD35974} [2013-01-29]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2013-01-29]
FF Extension: hmmXP - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{224d6e00-0336-11dd-95ff-0800200c9a66} [2013-01-29]
FF Extension: 8 Ultimo - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{2b6788a0-0ccd-11e1-be50-0800200c9a66} [2013-01-29]
FF Extension: HostIP.info Geolocation Plugin - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{49eba0b5-0393-4e13-8cc4-06298a281c5d} [2013-01-29]
FF Extension: Aero Fox XL - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66} [2013-01-29]
FF Extension: FT DeepDark - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2015-02-27]
FF Extension: W3v8 for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{7DA90D46-1B69-4cc5-9ACE-CB64D8D85B00} [2013-01-29]
FF Extension: iMacros for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2015-02-19]
FF Extension: Nightly Tester Tools - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29} [2013-11-01]
FF Extension: Proto_Dust - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{8a39fe10-f553-11dd-87af-0800200c9a66} [2013-01-29]
FF Extension: Live HTTP Headers - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2013-06-12]
FF Extension: Bamboo Feed Reader - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{b2e69492-2358-071a-7056-24ad0c3defb1} [2015-02-21]
FF Extension: Gnome - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{bdc06860-70c3-11dd-ad8b-0800200c9a66} [2013-01-29]
FF Extension: iPox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{c9c58820-7bd4-11da-a72b-0800200c9a66} [2013-01-29]
FF Extension: User Agent Switcher - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1} [2013-01-29]
FF Extension: PageZoom [de] - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{eeb299da-31d8-4683-aad4-9c9a045e0351} [2013-01-29]
FF Extension: CustomizeGoogle - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb} [2013-01-29]
FF Extension: SEOpen - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{ff6bdc07-eed6-4815-ad95-d7938b673ab5} [2013-01-29]
FF Extension: Classic Theme Restorer - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-06-16]
FF Extension: Classic Toolbar Buttons - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2014-06-19]
FF Extension: Firebug - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\firebug@software.joehewitt.com.xpi [2013-01-29]
FF Extension: Ghostery - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\firefox@ghostery.com.xpi [2015-02-24]
FF Extension: Glaze Black - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\glaze_black@www.theme-oasis.org.xpi [2013-01-29]
FF Extension: ipFuck - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\ipfuck@p4ul.info.xpi [2014-03-07]
FF Extension: Lightbeam - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2013-01-29]
FF Extension: NASA Night Launch - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\nasanightlaunch@example.com.xpi [2013-01-29]
FF Extension: Netscape Navigator Nostalgia - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\Netscape@gideas.xpi [2013-01-29]
FF Extension: Niederschlagsradar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\niederschlagsradar@sensiva.net.xpi [2013-01-29]
FF Extension: Classic Compact Options - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\notreal.ccoptions@environmentalchemistry.com.xpi [2013-01-29]
FF Extension: RightBar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\rightbar@realmtech.net.xpi [2014-06-19]
FF Extension: Secret Agent - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\SecretAgent@Dephormation.org.uk.xpi [2014-03-12]
FF Extension: Secure Login - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\secureLogin@blueimp.net.xpi [2015-02-11]
FF Extension: MZ8 - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\someone@somewhere.xpi [2014-07-27]
FF Extension: Throbber Restored - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\Throbber-Restored@jetpack.xpi [2014-09-07]
FF Extension: Flagfox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-10]
FF Extension: Image Zoom - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2013-04-16]
FF Extension: Aeon Colors - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1DEAE5AA-E19E-458b-9C8C-73CB651B9A58}.xpi [2013-01-29]
FF Extension: LittleFox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}.xpi [2014-06-20]
FF Extension: Leet Key - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{3335F91D-2AEF-4097-B831-C96C60349822}.xpi [2013-01-29]
FF Extension: Organize Status Bar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{35106bca-6c78-48c7-ac28-56df30b51d2c}.xpi [2013-01-29]
FF Extension: Qute Classic - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{5514CFC3-D9A8-4f1a-8DF1-930EBFB59901}.xpi [2013-01-29]
FF Extension: STEAM - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{678156d0-0e01-11df-8a39-0800200c9a66}.xpi [2013-01-29]
FF Extension: Nautipolis for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{6C4BAFB6-2AC2-4405-A98D-546B55B3AE92}.xpi [2013-01-29]
FF Extension: NoScript - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-01-29]
FF Extension: ReloadEvery - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2013-01-29]
FF Extension: n2scape - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{962229ad-1a31-4d4f-ac5b-a86cbc38f6bb}.xpi [2013-01-29]
FF Extension: Tamper Data - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi [2013-01-29]
FF Extension: Video DownloadHelper - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-03-06]
FF Extension: Sothink Flash Downloader for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{BAEBEF65-9289-47c5-8524-C345CC5D860D}.xpi [2013-01-29]
FF Extension: Web Developer - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2013-01-29]
FF Extension: classiccompact - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{D46E8522-6E86-44b1-A622-58C0668AD78E}.xpi [2013-01-29]
FF Extension: FOXSCAPE - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{da7f40f0-8675-11db-b606-0800200c9a66}.xpi [2013-01-29]
FF Extension: DownThemAll! - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2013-01-29]
FF Extension: Torbutton - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}.xpi [2013-01-29]
FF Extension: HackBar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{F5DDF39C-9293-4d5e-9AA8-E04E6DD5E9B4}.xpi [2013-10-05]
FF Extension: Mosaic-Fox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{f9bddc00-152b-11de-8c30-0800200c9a66}.xpi [2013-01-29]
FF Extension: Firefox 2, the theme, reloaded - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{fd2f951f-77ea-4938-9493-0c892c027a13}.xpi [2014-06-19]
FF Extension: QuickStores-Toolbar - C:\Program Files\Mozilla Firefox\extensions\quickstores@quickstores.de.xpi [2015-03-22]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

Locked "vdrv1000" service was unlocked successfully. <===== ATTENTION

S4 CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-20] ()
S4 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [70952 2011-03-31] (CyberLink)
S4 CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [312616 2011-03-31] (CyberLink)
R2 DokanMounter; C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe [22736 2014-08-25] ()
R2 EMET_Service; C:\Program Files\EMET 5.1\EMET_Service.exe [31880 2014-11-09] (Microsoft Corporation)
S3 Futuremark SystemInfo Service; C:\Program Files\Futuremark\SystemInfo\FMSISvc.exe [614624 2015-02-09] (Futuremark)
S3 ICCS; C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 IswSvc; C:\Program Files\CheckPoint\AKL\AkSVC.exe [749176 2014-05-14] (Check Point Software Technologies LTD)
S2 nlndis; C:\Program Files\NetLimiter Ndis Miniport Service\nlndis.exe [32768 2011-10-05] (Locktime Software) [File not signed]
S3 nlsvc; C:\Program Files\NetLimiter 3\nlsvc.exe [1126400 2013-02-20] (Locktime Software) [File not signed]
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2505160 2013-01-07] (O&O Software GmbH)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [32568 2014-08-07] (The OpenVPN Project)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1910640 2015-03-04] (Electronic Arts)
S4 Razer Game Scanner Service; C:\Program Files\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-02-05] ()
S3 Realtek87B; C:\Program Files\Realtek\RTL8187 Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed]
S2 RUBotSrv; C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe [443416 2013-07-25] (Trend Micro Inc.)
S4 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-01-14] (Crawler.com)
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 VC10SecS; C:\Program Files\Virtual CD v10\System\VC10SecS.exe [144712 2011-10-19] (H+H Software GmbH)
R2 VMAuthdService; C:\Program Files\VMware\VMware Workstation\vmware-authd.exe [86744 2014-06-12] (VMware, Inc.)
R2 VMnetDHCP; C:\Windows\system32\vmnetdhcp.exe [359128 2014-06-12] (VMware, Inc.)
R2 VMUSBArbService; C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [722624 2014-02-27] (VMware, Inc.)
R2 VMware NAT Service; C:\Windows\system32\vmnat.exe [437976 2014-06-12] (VMware, Inc.)
S2 VMwareHostd; C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe [14407384 2014-06-12] ()
S3 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3592120 2014-05-30] (Check Point Software Technologies Ltd.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [90936 2014-05-29] (Check Point Software Technologies, Ltd.)
R2 ZoneAlarm AntiTheft; C:\Program Files\CheckPoint\AntiTheft\Antitheft.exe [3128968 2014-05-30] (Check Point Software Technologies Ltd.)
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 catchme; C:\Users\Friedrich\AppData\Local\Temp\catchme.sys [31744 2015-03-23] () [File not signed]
S3 CrystalSysInfo; C:\Program Files\MediaCoder\SysInfo.sys [15152 2007-09-25] ()
R2 Dokan; C:\Windows\system32\drivers\dokan.sys [105680 2014-08-25] (Windows (R) Win 7 DDK provider)
S3 ENTECH; C:\Windows\system32\DRIVERS\ENTECH.sys [21664 2004-10-25] (EnTech Taiwan) [File not signed]
S3 es1371; C:\Windows\System32\drivers\es1371mp.sys [40832 2002-06-03] (Creative Technology Ltd.)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
S3 GKBFltr; C:\Windows\System32\Drivers\GameKB.sys [19328 2009-12-29] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R2 hcmon; C:\Windows\system32\drivers\hcmon.sys [43840 2014-02-27] (VMware, Inc.)
S3 HH10Help.sys; C:\Windows\system32\drivers\HH10Help.sys [13952 2010-03-10] (H+H Software GmbH) [File not signed]
R0 iaStorA; C:\Windows\System32\drivers\iaStorA.sys [532536 2012-09-01] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [25656 2012-09-01] (Intel Corporation)
S3 icsak; C:\Program Files\CheckPoint\AKL\ak\icsak.sys [39296 2014-05-14] (Check Point Software Technologies LTD)
R2 ISWKL; C:\Program Files\CheckPoint\AKL\ISWKL.sys [42880 2014-05-14] (Check Point Software Technologies LTD)
R0 iusb3hcs; C:\Windows\System32\drivers\iusb3hcs.sys [16880 2013-02-22] (Intel Corporation)
R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [352752 2013-02-22] (Intel Corporation)
R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [796656 2013-02-22] (Intel Corporation)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-04-30] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [488032 2014-04-30] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2014-04-30] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [43608 2014-04-30] (Kaspersky Lab)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144352 2014-04-30] (Kaspersky Lab ZAO)
R3 MBfilt; C:\Windows\System32\drivers\MBfilt32.sys [24664 2009-11-18] (Creative Technology Ltd.)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-02] (Intel Corporation)
R3 NLNdisMP; C:\Windows\System32\DRIVERS\nlndis.sys [5230088 2011-03-21] (Locktime Software)
S3 NLNdisPT; C:\Windows\System32\DRIVERS\nlndis.sys [5230088 2011-03-21] (Locktime Software)
R1 nltdi; C:\Program Files\NetLimiter 3\nltdi.sys [5281672 2011-03-21] (Locktime Software)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R2 ntk_PowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [71664 2011-04-20] (Cyberlink Corp.)
R2 ParagonLDM; C:\Windows\system32\drivers\biont_bs.sys [24512 2014-04-11] (Paragon Software GmbH)
S3 pneteth; C:\Windows\System32\DRIVERS\pneteth.sys [13440 2011-11-24] (June Fabrics Technology Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
S3 RTCore32; C:\Program Files\MSI Afterburner\RTCore32.sys [5632 2013-03-11] () [File not signed]
S3 RTL8187; C:\Windows\System32\DRIVERS\rtl8187.sys [375808 2010-01-07] (Realtek Semiconductor Corporation                          )
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [35624 2014-12-17] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [20416 2015-02-05] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [97088 2014-11-17] (Razer, Inc.)
R3 rzudd; C:\Windows\System32\DRIVERS\rzudd.sys [151336 2014-12-30] (Razer Inc)
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP2\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware)
R0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [436792 2013-01-30] () [File not signed]
R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
R0 SscRdBus; C:\Windows\System32\DRIVERS\SscRdBus.sys [88296 2014-11-22] (SuperSpeed LLC) [File not signed]
R0 SscRdCls; C:\Windows\System32\DRIVERS\SscRdCls.sys [40984 2007-12-19] (SuperSpeed LLC)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [23040 2014-04-08] (The OpenVPN Project)
S3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [5120 2012-12-19] ()
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [91016 2013-12-26] ()
R1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [20616 2013-12-26] ()
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [540168 2013-12-26] ()
S1 Uim_Vim; C:\Windows\System32\Drivers\Uim_Vim.sys [283600 2012-11-22] (Paragon)
R1 vdrv1000; C:\Windows\System32\DRIVERS\vdrv1000.sys [186392 2011-04-19] (H+H Software GmbH)
R3 vmkbd2; C:\Windows\system32\drivers\VMkbd.sys [26456 2014-06-12] (VMware, Inc.)
R3 VMnetAdapter; C:\Windows\System32\DRIVERS\vmnetadapter.sys [17104 2014-06-12] (VMware, Inc.)
R2 VMnetBridge; C:\Windows\System32\DRIVERS\vmnetbridge.sys [37456 2014-06-12] (VMware, Inc.)
R2 VMnetuserif; C:\Windows\system32\drivers\vmnetuserif.sys [26968 2014-06-12] (VMware, Inc.)
R2 vmx86; C:\Windows\system32\Drivers\vmx86.sys [66136 2014-06-12] (VMware, Inc.)
R3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [172416 2010-11-20] (Microsoft Corporation)
R1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [48128 2010-11-20] (Microsoft Corporation)
R3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2010-11-20] (Microsoft Corporation)
R1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [296064 2010-11-20] (Microsoft Corporation)
R1 Vsdatant; C:\Windows\System32\drivers\vsdatant.sys [456088 2014-05-30] (Check Point Software Technologies Ltd.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [63824 2013-10-08] (VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\System32\drivers\vstor2-mntapi20-shared.sys [23632 2013-02-22] (VMware, Inc.)
R2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam.sys [1068216 2012-04-15] (Windows (R) Win 7 DDK provider)
R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22856 2010-04-27] (Logitech Inc.)
S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [37704 2010-04-27] (Logitech Inc.)
S3 WmHidLo; C:\Windows\System32\drivers\WmHidLo.sys [31816 2010-04-27] (Logitech Inc.)
R3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [15048 2010-04-27] (Logitech Inc.)
R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66632 2010-04-27] (Logitech Inc.)
S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [465408 2009-07-14] (Microsoft Corporation)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [77296 2011-04-12] (CyberLink Corp.)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2014-04-30] (Kaspersky Lab ZAO)
S4 NvStUSB; \SystemRoot\system32\drivers\nvstusb.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-23 05:28 - 2015-03-23 05:28 - 00038697 _____ () C:\Users\Friedrich\Desktop\FRST.txt
2015-03-23 05:27 - 2015-03-22 22:23 - 01135104 _____ (Farbar) C:\Users\Friedrich\Desktop\FRST.exe
2015-03-23 05:00 - 2015-03-23 04:28 - 00360448 _____ () C:\Users\Friedrich\Desktop\CF-DeQuarantine.exe
2015-03-23 04:23 - 2015-03-23 04:24 - 00014178 _____ () C:\Users\Friedrich\Desktop\SystemLook.txt
2015-03-23 04:22 - 2015-03-23 04:21 - 00139264 _____ () C:\Users\Friedrich\Desktop\SystemLook.exe
2015-03-23 04:02 - 2015-03-23 04:02 - 00012836 _____ () C:\Users\Friedrich\Desktop\ComboFix.txt
2015-03-23 04:01 - 2015-03-23 04:02 - 00000000 ___SD () C:\Combo-Fix
2015-03-23 03:21 - 2015-03-23 03:35 - 00000000 ____D () C:\Qoobox
2015-03-23 03:21 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-03-23 03:21 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-03-23 03:21 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-03-23 03:21 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-03-23 03:21 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-03-23 03:21 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-03-23 03:21 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-03-23 03:21 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-03-23 03:20 - 2015-03-23 03:43 - 00000000 ____D () C:\Windows\erdnt
2015-03-23 03:18 - 2015-03-23 03:18 - 05616289 ____R (Swearware) C:\Users\Friedrich\Desktop\Combo-Fix.exe
2015-03-23 03:07 - 2015-03-23 05:28 - 00000000 ____D () C:\FRST
2015-03-23 02:18 - 2015-03-23 02:18 - 00076230 _____ () C:\Users\Friedrich\Documents\pinfect.zip
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\VDLL.DLL
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\system32\runouce.exe
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\rundll16.exe
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\RUNDL132.EXE
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\logo1_.exe
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\logo_1.exe
2015-03-23 00:29 - 2015-03-23 00:40 - 00000054 _____ () C:\Windows\Lic.xxx
2015-03-23 00:29 - 2015-03-23 00:29 - 00034048 _____ (MicroWorld Technologies Inc.) C:\Windows\system32\eEmpty.exe
2015-03-23 00:29 - 2015-03-23 00:29 - 00000000 ____D () C:\ProgramData\MicroWorld
2015-03-23 00:29 - 2015-03-23 00:29 - 00000000 ____D () C:\Program Files\Common Files\MicroWorld
2015-03-23 00:29 - 2005-09-22 23:22 - 00000522 _____ () C:\Windows\system32\Microsoft.VC80.CRT.manifest
2015-03-23 00:26 - 2015-03-22 23:23 - 00013312 _____ () C:\Users\Friedrich\Desktop\find.bat
2015-03-23 00:25 - 2015-03-22 23:27 - 68866904 _____ () C:\Users\Friedrich\Desktop\mwav.exe
2015-03-23 00:22 - 2015-03-23 05:28 - 00000000 ____D () C:\Users\Friedrich\Desktop\Sammlung fürs Board
2015-03-22 20:37 - 2015-03-22 20:37 - 00000000 ____D () C:\ProgramData\Trend Micro
2015-03-22 20:25 - 2015-03-22 20:28 - 00000353 _____ () C:\Users\Friedrich\Desktop\Office AUTOKMS sehr Wichtig.txt
2015-03-22 19:00 - 2015-03-22 19:00 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-03-22 18:34 - 2015-03-22 18:36 - 31973976 _____ (MiniTool Solution Ltd. ) C:\Users\Friedrich\Desktop\pwfree9.exe
2015-03-22 18:29 - 2015-03-22 18:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-21 18:11 - 2015-03-21 18:11 - 00290376 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmcomm.sys
2015-03-21 18:11 - 2015-03-21 18:11 - 00131744 _____ (trend_company_name) C:\Windows\system32\Drivers\tmrkb.sys
2015-03-20 23:13 - 2015-03-20 23:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro RUBotted
2015-03-20 23:13 - 2015-03-20 23:13 - 00000000 ____D () C:\Program Files\Trend Micro
2015-03-20 22:57 - 2015-03-20 22:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft HiJackFree
2015-03-20 22:57 - 2015-03-20 22:57 - 00000000 ____D () C:\Program Files\Emsisoft HiJackFree
2015-03-20 22:56 - 2015-03-20 22:56 - 02925920 _____ (Emsisoft GmbH ) C:\Users\Friedrich\Desktop\EmsisoftHiJackFreeSetup.exe
2015-03-20 22:47 - 2015-03-20 22:51 - 140425968 _____ (Microsoft Corporation) C:\Users\Friedrich\Desktop\Microsoft Security Scanner.exe
2015-03-20 19:07 - 2015-03-20 19:11 - 00000000 ____D () C:\TDSSKiller_Quarantine
2015-03-19 01:28 - 2015-03-19 02:52 - 00000000 ____D () C:\Users\Friedrich\Desktop\ThinkpadpunkteVideo
2015-03-19 00:53 - 2015-03-22 19:01 - 00429152 _____ () C:\Users\Friedrich\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-19 00:52 - 2015-03-22 19:12 - 04703120 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-19 00:18 - 2015-03-19 00:20 - 00084562 _____ () C:\Users\Friedrich\Desktop\usbdeview.zip
2015-03-19 00:18 - 2015-03-19 00:20 - 00046516 _____ () C:\Users\Friedrich\Desktop\driverview.zip
2015-03-19 00:17 - 2015-03-19 00:20 - 00068998 _____ () C:\Users\Friedrich\Desktop\bluescreenview.zip
2015-03-18 21:39 - 2015-03-18 21:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GNavigia
2015-03-18 21:39 - 2010-04-07 02:29 - 00081920 _____ () C:\Windows\system32\GkSui20.EXE
2015-03-18 21:26 - 2015-03-18 21:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2015-03-18 21:26 - 2015-03-16 18:44 - 00749664 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2015-03-18 21:25 - 2015-03-18 21:25 - 00000000 ____D () C:\Program Files\Oracle
2015-03-18 21:25 - 2015-03-16 18:42 - 00104384 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2015-03-18 21:17 - 2015-03-18 21:17 - 00000000 ____D () C:\Windows\system32\RTCOM
2015-03-18 21:16 - 2014-12-03 13:51 - 00927960 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll
2015-03-18 21:16 - 2014-12-03 11:41 - 03365208 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys
2015-03-18 21:16 - 2014-12-03 10:15 - 01485163 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2015-03-18 21:16 - 2014-12-02 11:42 - 02381680 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll
2015-03-18 21:16 - 2014-11-27 08:31 - 02510192 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO.dll
2015-03-18 21:16 - 2014-08-06 06:43 - 02588888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll
2015-03-18 21:16 - 2014-04-10 05:19 - 01940056 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2015-03-18 21:16 - 2014-03-06 09:35 - 01892056 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl
2015-03-18 21:16 - 2014-02-18 10:04 - 02421792 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2015-03-18 21:16 - 2014-01-08 08:25 - 00332568 _____ (Creative Technology Ltd.) C:\Windows\system32\MBWrp32.dll
2015-03-18 21:16 - 2013-01-11 09:27 - 00563992 _____ (Creative Technology Ltd.) C:\Windows\system32\MBTHX32.dll
2015-03-18 21:16 - 2011-11-22 09:28 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT32.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA32.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG32A.dll
2015-03-18 21:16 - 2010-09-27 02:34 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2015-03-18 21:16 - 2009-12-04 08:43 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSXT.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSHD.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP360.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW.dll
2015-03-18 21:16 - 2009-11-18 11:42 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesLib.dll
2015-03-18 21:16 - 2009-11-18 00:12 - 00024664 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\MBfilt32.sys
2015-03-18 21:15 - 2014-06-06 17:00 - 00519368 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll
2015-03-18 21:15 - 2013-10-11 05:47 - 00092584 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-03-18 21:15 - 2012-03-08 04:47 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll
2015-03-18 20:49 - 2015-01-25 11:20 - 00000000 ____D () C:\Users\Friedrich\Desktop\Baphomets Fluch 1-5 Deutsch
2015-03-17 14:44 - 2015-03-18 17:10 - 329252864 _____ () C:\Users\Friedrich\Desktop\openSUSE-13.2-DVD-i586.iso
2015-03-17 14:37 - 2015-03-17 14:41 - 79691776 _____ () C:\Users\Friedrich\Desktop\CorePlus-current.iso
2015-03-16 18:42 - 2015-03-16 18:42 - 00115672 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetAdp.sys
2015-03-12 15:27 - 2015-03-23 05:05 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Everything
2015-03-12 15:27 - 2015-03-12 15:27 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Everything
2015-03-11 20:41 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-03-11 20:41 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-03-11 20:41 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2015-03-11 20:02 - 2015-03-06 06:15 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-11 20:02 - 2015-03-06 06:15 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-11 20:02 - 2015-03-06 06:10 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-11 20:02 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-11 20:02 - 2015-03-06 06:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-11 20:02 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-11 20:02 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-11 20:02 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-11 20:02 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 20:02 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 20:02 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 20:02 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 20:02 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 20:02 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 20:02 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 20:02 - 2015-02-20 03:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 20:02 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 20:02 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-11 20:02 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-11 20:02 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 20:02 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 20:02 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 20:02 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-11 20:02 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-11 20:02 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 20:02 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 20:02 - 2015-02-20 02:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-11 20:02 - 2015-02-20 02:50 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 20:02 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 20:02 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-11 20:02 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 20:02 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 20:02 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 20:02 - 2015-02-20 02:24 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-11 20:02 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-11 20:02 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 20:02 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 20:02 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 20:02 - 2015-01-31 00:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-11 20:02 - 2015-01-29 04:05 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-03-11 20:02 - 2015-01-29 04:05 - 03917752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-11 20:02 - 2015-01-29 04:01 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-11 20:02 - 2015-01-29 04:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-11 20:02 - 2015-01-29 03:57 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-11 20:01 - 2015-02-26 04:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 20:01 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 20:01 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 20:01 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 20:01 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 20:01 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 20:01 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 20:01 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 20:00 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-03-11 17:12 - 2015-03-11 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PY Software
2015-03-11 17:12 - 2007-08-13 14:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\wmvdmoe.dll
2015-03-11 16:57 - 2015-03-11 17:03 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\WebcamZoneTrigger
2015-03-11 16:12 - 2015-03-11 16:12 - 00000000 ____D () C:\Users\Public\Documents\Xeoma
2015-03-11 12:19 - 2015-03-11 12:19 - 00000000 ____D () C:\Windows\system32\DCS
2015-03-11 01:10 - 2015-03-11 01:10 - 00003584 _____ () C:\Users\Friedrich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-08 10:55 - 2015-03-08 10:55 - 06208736 _____ (Tim Kosse) C:\Users\Friedrich\Downloads\FileZilla_3.10.2_win32-setup.exe
2015-03-08 10:55 - 2015-03-08 10:55 - 06057862 _____ (Tim Kosse) C:\Users\Friedrich\Downloads\FileZilla_3.9.0.5_win32-setup.exe
2015-03-08 03:47 - 2015-03-08 03:47 - 00000216 _____ () C:\Users\Friedrich\Desktop\rFactor Demo.url
2015-03-08 02:07 - 2015-03-08 02:07 - 00000623 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LEGO Batman 3 - Beyond Gotham.lnk
2015-03-08 02:02 - 2015-03-08 02:02 - 00000000 ____D () C:\Program Files\LEGO Batman 3 - Beyond Gotham
2015-03-06 05:12 - 2015-03-06 05:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Apple Computer
2015-03-06 05:10 - 2015-03-06 05:12 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-03-06 05:10 - 2015-03-06 05:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-03-06 05:08 - 2015-03-21 19:35 - 00000000 ____D () C:\Users\Friedrich\Desktop\LightWorks DE Tutorials
2015-03-06 04:28 - 2015-03-06 04:28 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-03-05 21:53 - 2015-03-05 21:53 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Stardock
2015-03-05 20:41 - 2015-03-13 19:42 - 00000000 ____D () C:\Users\Friedrich\Desktop\Chromanova.fm  - crazy freak dance 24-7-
2015-03-05 07:50 - 2015-03-05 07:50 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\com.ohnoo.TormentumDemo
2015-03-05 07:31 - 2015-03-05 07:31 - 00000000 ____D () C:\Users\Friedrich\Documents\SpriteLamp
2015-03-05 07:31 - 2015-03-05 07:31 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\SpriteLampWinforms
2015-03-05 06:58 - 2015-03-05 07:03 - 00000000 ____D () C:\Program Files\TClock
2015-03-05 06:04 - 2015-03-05 06:04 - 00000000 ____D () C:\Windows Anmeldesounds +Icons AlleSys Bildschirmschoner
2015-03-05 05:49 - 2015-03-05 05:49 - 00000000 ____D () C:\ProgramData\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 __HDC () C:\ProgramData\{9C3F823B-4738-4CAF-A6B2-69E87FB636C0}
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\Users\Public\Documents\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\Program Files\Stardock
2015-03-05 05:47 - 2015-03-05 05:47 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\PackageAware
2015-03-05 05:28 - 2015-03-05 05:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPU
2015-03-05 05:28 - 2015-03-05 05:28 - 00000000 ____D () C:\Program Files\MPU
2015-03-05 05:20 - 2015-03-05 05:20 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Lern-o-Mat
2015-03-05 05:14 - 2015-03-05 05:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD-lab PRO 2.0
2015-03-05 05:14 - 2015-03-05 05:14 - 00000000 ____D () C:\Program Files\DVDlabPro2
2015-03-05 05:13 - 2015-03-05 05:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Doc Scrubber
2015-03-05 05:13 - 2015-03-05 05:13 - 00000000 ____D () C:\Program Files\Doc Scrubber
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\jStrip
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jStrip
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\Program Files\jStrip
2015-03-05 05:12 - 1999-10-30 02:00 - 00167936 _____ (Common Controls Replacement Project (CCRP)) C:\Windows\system32\ccrpftv6.ocx
2015-03-04 06:03 - 2015-03-12 12:34 - 00000000 ____D () C:\Users\Friedrich\.mediathek3
2015-03-04 06:03 - 2015-03-04 06:03 - 00000000 ____D () C:\Program Files\Mediathekview
2015-03-03 19:32 - 2015-03-03 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2015-03-03 19:32 - 2015-03-03 19:32 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2015-03-03 18:52 - 2015-03-03 18:54 - 63361024 _____ () C:\Users\Friedrich\Desktop\EpicGamesLauncherInstaller-2.0.0-2465596.msi
2015-03-03 18:13 - 2015-03-03 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
2015-03-02 07:05 - 2015-03-02 07:05 - 00000000 ____D () C:\Users\Friedrich\Documents\Bandicam
2015-03-02 07:04 - 2015-03-03 19:12 - 00000000 ____D () C:\Program Files\Bandicam
2015-03-02 07:04 - 2015-03-02 07:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2015-03-02 07:04 - 2015-03-02 07:04 - 00000000 ____D () C:\Program Files\BandiMPEG1
2015-03-01 23:52 - 2015-03-01 23:52 - 00000000 ____D () C:\Users\Friedrich\Desktop\Silent Hill Downpour (Xbox 360 Gamerip)
2015-02-28 18:06 - 2015-02-05 18:51 - 00621384 _____ (NVIDIA Corporation) C:\Windows\system32\nvStreaming.exe
2015-02-28 18:05 - 2015-02-05 21:48 - 24768144 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 20465808 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 16016848 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 10773520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 10713256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 08473928 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-02-28 18:05 - 2015-02-05 21:48 - 03247248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 01047880 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3234752.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00931136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00912528 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3234752.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00909120 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00877816 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshim.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00399504 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00345928 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00305136 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim32.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00164568 _____ (NVIDIA Corporation) C:\Windows\system32\nvinit.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00161424 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda32v.sys
2015-02-28 18:05 - 2015-02-05 21:48 - 00027280 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap32.dll
2015-02-27 16:04 - 2015-02-27 19:00 - 00000000 ____D () C:\Program Files\EMET 5.1
2015-02-27 16:04 - 2015-02-27 16:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit
2015-02-27 03:00 - 2015-02-27 03:00 - 00000216 _____ () C:\Users\Friedrich\Desktop\Tormentum - Dark Sorrow Demo.url
2015-02-26 18:36 - 2015-02-26 18:36 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cain
2015-02-26 18:36 - 2015-02-26 18:36 - 00000000 ____D () C:\Program Files\Cain
2015-02-24 19:24 - 2015-03-20 23:09 - 00000000 ____D () C:\Users\Friedrich\Documents\Survarium
2015-02-22 19:27 - 2015-02-22 19:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-23 05:28 - 2013-01-30 06:57 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\NetSpeedMonitor
2015-03-23 05:25 - 2013-01-30 04:08 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\vlc
2015-03-23 05:09 - 2013-01-30 01:23 - 00000000 ____D () C:\Users\Friedrich\Desktop\Sicherheitsprogramme
2015-03-23 04:26 - 2010-11-20 22:01 - 01639348 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-23 04:16 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-03-23 03:54 - 2009-07-14 05:34 - 00034848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-23 03:54 - 2009-07-14 05:34 - 00034848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-23 03:50 - 2013-01-29 18:50 - 01257627 _____ () C:\Windows\WindowsUpdate.log
2015-03-23 03:47 - 2013-02-17 07:38 - 00000000 ____D () C:\ProgramData\VMware
2015-03-23 03:46 - 2014-07-03 02:07 - 00067178 _____ () C:\Windows\setupact.log
2015-03-23 03:46 - 2014-01-11 03:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-03-23 03:46 - 2013-01-30 08:01 - 01833612 _____ () C:\Windows\system32\oodbs.lor
2015-03-23 03:46 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-23 03:38 - 2014-01-11 01:33 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Apps\2.0
2015-03-23 03:38 - 2013-01-30 05:14 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\CrashDumps
2015-03-23 03:38 - 2009-07-14 05:53 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-23 03:38 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2015-03-23 03:37 - 2014-07-05 01:41 - 00606602 _____ () C:\Windows\PFRO.log
2015-03-23 03:35 - 2013-01-29 18:50 - 00000000 ____D () C:\Users\Friedrich
2015-03-23 03:03 - 2014-07-05 01:31 - 00000000 ____D () C:\AdwCleaner
2015-03-23 02:47 - 2014-11-16 21:36 - 00000000 ____D () C:\Program Files\Spezial 5.0
2015-03-23 00:14 - 2014-03-23 15:43 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-03-23 00:03 - 2014-11-15 20:35 - 00107224 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-23 00:01 - 2014-03-23 15:42 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-22 22:33 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-03-22 22:10 - 2013-01-30 01:23 - 00000000 ____D () C:\Users\Friedrich\Desktop\Weitere Programme
2015-03-22 21:36 - 2013-03-02 16:35 - 00000000 ____D () C:\Program Files\Pluto Client
2015-03-22 21:36 - 2013-01-30 06:18 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\NoNameScript
2015-03-22 20:24 - 2014-10-20 17:53 - 00000000 ____D () C:\ProgramData\GalaxyClient
2015-03-22 19:59 - 2013-01-30 06:17 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\mIRC
2015-03-22 19:56 - 2013-01-30 06:17 - 00000000 ____D () C:\Program Files\mIRC
2015-03-22 19:03 - 2013-11-22 18:50 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\AIMP3
2015-03-22 19:03 - 2013-01-30 03:24 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-22 18:56 - 2014-05-14 17:55 - 00000000 ____D () C:\Users\Friedrich\Desktop\Rap Mai 2014
2015-03-22 18:44 - 2013-02-06 04:46 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-22 18:23 - 2014-02-07 14:18 - 00000600 _____ () C:\Users\Friedrich\AppData\Roaming\winscp.rnd
2015-03-22 18:10 - 2014-08-20 05:17 - 00000000 ____D () C:\Windows\Minidump
2015-03-21 06:12 - 2013-01-30 05:49 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-03-20 22:23 - 2013-02-06 02:07 - 00000000 ____D () C:\Temp
2015-03-20 21:39 - 2013-01-30 06:49 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2015-03-20 19:34 - 2014-05-04 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WhoCrashed
2015-03-20 19:34 - 2014-05-04 18:34 - 00000000 ____D () C:\Program Files\WhoCrashed
2015-03-20 18:06 - 2013-02-01 15:18 - 00000000 ____D () C:\Program Files\Vuze
2015-03-19 07:56 - 2013-01-29 23:12 - 00000000 ____D () C:\Windows\pss
2015-03-19 06:48 - 2013-03-25 17:56 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\NPE
2015-03-19 06:04 - 2013-06-04 01:27 - 00000000 ____D () C:\Stinger_Quarantine
2015-03-19 06:04 - 2013-02-05 00:25 - 00000000 ____D () C:\Program Files\stinger
2015-03-19 03:53 - 2013-01-30 08:07 - 00000000 ____D () C:\Program Files\Steam
2015-03-19 02:39 - 2013-03-04 20:10 - 00000000 ____D () C:\Program Files\KaloMa
2015-03-19 00:48 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-03-19 00:26 - 2014-06-16 02:02 - 00064681 ____H () C:\Windows\system32\BTImages.dat
2015-03-19 00:25 - 2013-01-25 15:30 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-03-19 00:21 - 2013-02-04 05:24 - 00000000 ____D () C:\Program Files\USB Deview
2015-03-19 00:20 - 2014-09-14 21:01 - 00000000 ____D () C:\Program Files\Bluescreen View
2015-03-19 00:20 - 2014-02-14 02:24 - 00000000 ____D () C:\Program Files\DriverView v1.45
2015-03-18 22:11 - 2013-07-16 15:55 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\FileZilla
2015-03-18 21:27 - 2014-02-24 06:30 - 00000000 ____D () C:\Users\Friedrich\.VirtualBox
2015-03-18 21:17 - 2013-01-25 15:37 - 00000000 ___HD () C:\Program Files\Temp
2015-03-18 21:04 - 2013-02-01 15:18 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Azureus
2015-03-18 19:33 - 2013-01-30 01:31 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\KeePass
2015-03-18 18:45 - 2013-02-17 08:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\VMware
2015-03-18 18:45 - 2013-02-17 08:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\VMware
2015-03-18 14:57 - 2013-01-30 01:20 - 00042222 _____ () C:\Users\Friedrich\NeueDatenbank.kdbx
2015-03-16 21:48 - 2013-01-30 01:16 - 00000000 ____D () C:\Users\Friedrich\Mädels u. Chatter
2015-03-16 14:56 - 2015-02-09 11:04 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\.Tribler
2015-03-15 13:50 - 2013-01-31 03:07 - 00000000 ____D () C:\Program Files\Trillian
2015-03-14 17:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2015-03-12 16:44 - 2014-08-17 15:52 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Adobe
2015-03-12 16:44 - 2013-01-29 22:44 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-12 16:44 - 2013-01-29 22:44 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-12 15:27 - 2013-02-01 15:44 - 00000000 ____D () C:\Program Files\Search Everything
2015-03-12 15:24 - 2013-03-19 12:11 - 00000000 ____D () C:\Windows\system32\MAGIX
2015-03-12 15:19 - 2013-01-30 02:18 - 00000000 ____D () C:\Users\Friedrich\Desktop\Spiele
2015-03-12 01:23 - 2013-02-01 16:32 - 00000000 ____D () C:\ProgramData\Origin
2015-03-11 20:42 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-03-11 20:32 - 2014-02-19 19:09 - 00000000 ___RD () C:\Users\Friedrich\Virtual Machines
2015-03-11 20:17 - 2013-08-03 23:48 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-11 15:19 - 2013-01-29 22:28 - 00007655 _____ () C:\Users\Friedrich\AppData\Local\Resmon.ResmonCfg
2015-03-11 13:36 - 2014-07-24 00:39 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\.minecraft
2015-03-11 13:26 - 2013-02-07 04:13 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Razer
2015-03-11 13:26 - 2013-02-07 04:12 - 00000000 ____D () C:\ProgramData\Razer
2015-03-11 13:26 - 2013-01-30 05:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-03-11 13:26 - 2013-01-30 05:03 - 00000000 ____D () C:\Program Files\Razer
2015-03-11 12:11 - 2013-08-21 03:42 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\midori
2015-03-11 02:35 - 2013-02-06 02:14 - 00000000 ____D () C:\ProgramData\TEMP
2015-03-10 04:18 - 2014-06-24 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SRWare Iron
2015-03-10 04:18 - 2014-06-24 16:21 - 00000000 ____D () C:\Program Files\SRWare Iron
2015-03-09 09:57 - 2013-04-11 01:04 - 00000000 ____D () C:\Program Files\SpeedFan
2015-03-09 08:08 - 2014-08-23 16:30 - 00000000 ____D () C:\Users\Friedrich\Desktop\New Handy Root und ähnliches Tutorials
2015-03-08 10:56 - 2013-07-16 15:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-03-08 10:56 - 2013-07-16 15:55 - 00000000 ____D () C:\Program Files\FileZilla FTP Client
2015-03-08 04:48 - 2014-01-22 17:33 - 00000000 ____D () C:\Users\Friedrich\.dbus-keyrings
2015-03-08 04:25 - 2014-07-15 21:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live
2015-03-08 04:25 - 2014-07-15 21:51 - 00000000 ____D () C:\Program Files\GameforgeLive
2015-03-08 03:47 - 2014-04-09 00:13 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-03-08 02:35 - 2013-11-19 10:19 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Warner Bros. Interactive Entertainment
2015-03-06 05:11 - 2013-02-14 06:50 - 00000000 ____D () C:\Program Files\QuickTime
2015-03-06 04:28 - 2013-09-19 21:42 - 00000000 ____D () C:\ProgramData\Oracle
2015-03-06 04:25 - 2014-01-15 06:51 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-03-06 04:25 - 2013-03-05 05:07 - 00000000 ____D () C:\Program Files\Java
2015-03-05 08:01 - 2013-08-13 00:14 - 00000000 ____D () C:\Users\Friedrich\Documents\3DMark
2015-03-05 07:58 - 2014-06-16 05:52 - 00000022 _____ () C:\Windows\GPU-Z.INI
2015-03-05 07:04 - 2013-01-29 23:29 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-03-05 07:04 - 2013-01-29 23:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-03-05 05:28 - 2013-02-05 07:26 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2015-03-05 05:11 - 2013-02-07 01:16 - 00000000 ____D () C:\Westwood
2015-03-05 05:10 - 2013-02-07 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Westwood
2015-03-05 03:01 - 2014-04-11 03:10 - 00000000 ____D () C:\Program Files\prime95 v279
2015-03-05 02:40 - 2015-02-11 15:43 - 00000000 ____D () C:\Users\Friedrich\Desktop\Spionaufnahmen mit LifeCam
2015-03-05 02:18 - 2015-02-12 12:20 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\GetRight
2015-03-04 05:16 - 2014-03-11 20:56 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\MPC-HC
2015-03-04 01:56 - 2013-02-01 16:32 - 00000000 ____D () C:\Program Files\Origin
2015-03-04 00:57 - 2013-07-24 22:30 - 00000000 ____D () C:\HammerAutosave
2015-03-03 18:13 - 2013-11-22 18:50 - 00000000 ____D () C:\Program Files\AIMP3
2015-03-02 18:21 - 2013-01-30 02:15 - 00000000 ____D () C:\Users\Friedrich\Desktop\Ernährung u Sportinfos zusatz zur MAPPE
2015-03-02 02:15 - 2013-02-26 18:36 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Audacity
2015-03-02 02:11 - 2013-02-26 18:36 - 00001000 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-03-02 02:11 - 2013-02-26 18:36 - 00000000 ____D () C:\Program Files\Audacity
2015-03-01 23:47 - 2015-02-12 12:21 - 00000000 ____D () C:\ProgramData\GetRight
2015-02-28 19:33 - 2013-02-03 00:02 - 02712576 _____ () C:\Users\Friedrich\AppData\Local\file__0.localstorage
2015-02-28 18:06 - 2013-01-25 15:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-02-28 17:10 - 2013-05-10 04:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IsoBuster
2015-02-28 17:10 - 2013-05-10 04:41 - 00000000 ____D () C:\Program Files\IsoBuster
2015-02-27 17:38 - 2013-01-30 01:44 - 00000000 ____D () C:\Users\Friedrich\Desktop\Canon Shots
2015-02-27 16:52 - 2013-02-01 16:51 - 00000000 ____D () C:\Program Files\Futuremark
2015-02-27 16:03 - 2013-01-30 02:17 - 00000000 ____D () C:\Users\Friedrich\Desktop\POP-RADIO FAKE ACCOUNTS
2015-02-27 03:26 - 2013-02-26 18:48 - 00000000 ____D () C:\Users\Public\Documents\Lightworks
2015-02-27 03:20 - 2013-02-26 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightworks
2015-02-27 03:20 - 2013-02-26 18:48 - 00000000 ____D () C:\Program Files\Lightworks
2015-02-26 21:20 - 2011-04-28 16:10 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-26 18:36 - 2013-09-04 05:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cain
2015-02-26 18:36 - 2013-01-30 01:23 - 00000000 ____D () C:\Users\Friedrich\Desktop\Exploit Sets
2015-02-25 03:10 - 2014-06-28 07:22 - 00000000 ____D () C:\Users\Friedrich\Documents\EthanMeteorHunterDemo
2015-02-25 01:15 - 2013-01-30 01:16 - 00000000 ____D () C:\Users\Friedrich\Martin Krüger
2015-02-25 01:14 - 2013-05-24 01:11 - 00000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe PNG Format CS5 Prefs
2015-02-24 16:48 - 2013-01-29 23:37 - 00000000 ____D () C:\Program Files\CCleaner
2015-02-22 21:59 - 2014-08-10 15:52 - 00000000 ____D () C:\Users\Friedrich\Desktop\Fahrrad-Reperatur Hilfe
2015-02-22 19:27 - 2013-01-30 07:03 - 00000000 ____D () C:\Program Files\Google
2015-02-21 18:41 - 2015-02-17 21:27 - 00000101 _____ () C:\Users\Friedrich\Desktop\Titel Gammeltower video.txt

==================== Files in the root of some directories =======

2013-10-28 21:15 - 2013-07-08 17:34 - 2699264 _____ (wPrime) C:\Program Files\wPrime.exe
2014-04-26 21:08 - 2014-04-26 21:08 - 0000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe GIF Format CS5 Prefs
2013-05-24 01:11 - 2015-02-25 01:14 - 0000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe PNG Format CS5 Prefs
2013-08-06 07:11 - 2014-10-31 04:40 - 0000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe Targa Format CS5 Prefs
2015-02-03 18:40 - 2015-02-04 21:05 - 0000623 _____ () C:\Users\Friedrich\AppData\Roaming\All CPU MeterV3_Settings.ini
2013-03-04 20:09 - 2014-02-28 15:35 - 0000540 _____ () C:\Users\Friedrich\AppData\Roaming\AutoGK.ini
2013-05-22 21:43 - 2013-08-25 04:47 - 0000000 _____ () C:\Users\Friedrich\AppData\Roaming\bfe_cddrives
2015-02-04 01:26 - 2015-02-04 01:26 - 0001002 _____ () C:\Users\Friedrich\AppData\Roaming\Currency Meter_Settings.ini
2015-02-04 01:27 - 2015-02-04 01:28 - 0000841 _____ () C:\Users\Friedrich\AppData\Roaming\Drives Meter_Settings.ini
2015-02-03 19:19 - 2015-02-03 19:21 - 0000310 _____ () C:\Users\Friedrich\AppData\Roaming\Earthquakes Meter_Settings.ini
2014-04-20 21:35 - 2015-02-03 17:31 - 0000284 _____ () C:\Users\Friedrich\AppData\Roaming\GPU MeterV2_Settings.ini
2013-06-01 08:16 - 2013-09-22 08:28 - 0001870 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile0.dat
2013-06-01 08:16 - 2013-09-22 08:28 - 0001872 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile1.dat
2013-06-01 08:16 - 2013-09-22 08:28 - 0001876 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile2.dat
2013-09-22 08:27 - 2013-09-22 08:28 - 0001832 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile3.dat
2015-02-04 01:30 - 2015-02-04 01:30 - 0001209 _____ () C:\Users\Friedrich\AppData\Roaming\Network Meter_Settings.ini
2015-02-04 01:30 - 2015-02-04 01:30 - 0000008 _____ () C:\Users\Friedrich\AppData\Roaming\Network Meter_Usage.ini
2013-02-18 05:16 - 2014-07-16 01:03 - 0138904 _____ () C:\Users\Friedrich\AppData\Roaming\PnkBstrK.sys
2014-04-18 16:25 - 2014-07-02 10:13 - 14315520 _____ () C:\Users\Friedrich\AppData\Roaming\Sandra.mdb
2014-02-07 14:18 - 2015-03-22 18:23 - 0000600 _____ () C:\Users\Friedrich\AppData\Roaming\winscp.rnd
2013-11-15 04:48 - 2013-11-15 05:13 - 0001456 _____ () C:\Users\Friedrich\AppData\Local\Adobe Für Web speichern 12.0 Prefs
2013-10-29 18:14 - 2013-10-29 18:14 - 0242095 _____ () C:\Users\Friedrich\AppData\Local\ars.cache
2013-10-29 18:14 - 2013-10-29 18:14 - 0377163 _____ () C:\Users\Friedrich\AppData\Local\census.cache
2015-03-11 01:10 - 2015-03-11 01:10 - 0003584 _____ () C:\Users\Friedrich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-02-03 00:02 - 2015-02-28 19:33 - 2712576 _____ () C:\Users\Friedrich\AppData\Local\file__0.localstorage
2013-10-29 17:44 - 2013-10-29 17:44 - 0000036 _____ () C:\Users\Friedrich\AppData\Local\housecall.guid.cache
2014-02-09 23:50 - 2014-06-27 05:58 - 0000600 _____ () C:\Users\Friedrich\AppData\Local\PUTTY.RND
2015-02-02 18:15 - 2015-02-02 18:15 - 0000733 _____ () C:\Users\Friedrich\AppData\Local\recently-used.xbel
2013-01-29 22:28 - 2015-03-11 15:19 - 0007655 _____ () C:\Users\Friedrich\AppData\Local\Resmon.ResmonCfg
2013-03-19 12:49 - 2013-03-19 12:52 - 0000041 ___SH () C:\ProgramData\.zreglib

Files to move or delete:
====================
C:\Users\Friedrich\Bsb.exe
C:\Users\Friedrich\cc_20140124_180349.reg
C:\Users\Friedrich\cc_20140315_160443.reg
C:\Users\Friedrich\cc_20140718_151624.reg
C:\Users\Friedrich\cc_20140905_190648.reg
C:\Users\Friedrich\cc_20141008_060204.reg
C:\Users\Friedrich\IP_Log_Data.js
C:\Users\Friedrich\regsicherung.reg
C:\Users\Friedrich\Sicherung reg von CCleaner 2.reg


Some content of TEMP:
====================
C:\Users\Friedrich\AppData\Local\Temp\catchme.dll


Some zero byte size files/folders:
==========================
C:\Windows\logo1_.exe
C:\Windows\logo_1.exe
C:\Windows\RUNDL132.EXE
C:\Windows\rundll16.exe
C:\Windows\VDLL.DLL
C:\Windows\System32\runouce.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-20 19:59

==================== End Of Log ============================

--- --- ---

--- --- ---

Friedrich_ 23.03.2015 09:16

re2
 
FRST Addition-Log:
Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by Friedrich at 2015-03-23 05:29:22
Running from C:\Users\Friedrich\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ZoneAlarm Extreme Security Antivirus (Disabled - Up to date) {23B6D20A-C2DE-B3F5-C67D-07ECD854E6A9}
AS: ZoneAlarm Extreme Security Anti-Spyware (Disabled - Up to date) {98D733EE-E4E4-BC7B-FCCD-3C9EA3D3AC14}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Extreme Security Firewall (Disabled) {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

«City Car Driving»  Releases 1.3.2 (HKLM\...\{CC457F3D-5CDE-4CE8-9685-90A4EDE81374}_is1) (Version: 1.3.2 - Forward Development)
007 Legends 1.0.2 (HKLM\...\007 Legends 1.0.2) (Version: 1.0.2 - Activision Publishing)
3DMark (HKLM\...\{1f6ed41c-36d8-4cb3-82f4-cf7b25f60143}) (Version: 1.4.775.0 - Futuremark)
3DMark (Version: 1.4.775.0 - Futuremark) Hidden
3DMark 11 (HKLM\...\{f9e83b9c-ab7e-4005-8f32-4ea69703a5e4}) (Version: 1.0.132.0 - Futuremark)
3DMark 11 (Version: 1.0.132.0 - Futuremark) Hidden
3DMark03 (HKLM\...\{FF35F637-72B9-43BE-A281-06EB2854393A}) (Version: 3.6.0 - )
ACE COMBAT ASSAULT HORIZON Enhanced Edition (HKLM\...\ACE COMBAT ASSAULT HORIZON Enhanced Edition_is1) (Version:  - )
Active@ DVD Eraser v 1.1 (HKLM\...\Active@ DVD Eraser v 1.1) (Version:  - )
Activision(R) (Version: 1.00.0000 - Activision) Hidden
Adobe AIR (HKLM\...\Adobe AIR) (Version: 14.0.0.110 - Adobe Systems Incorporated)
Adobe Community Help (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Media Player (HKLM\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Photoshop CS5 (HKLM\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)
Adrenaline Sniper Elite V2 Benchmark Tool 1.0 (Build 1.0.0.1) (HKLM\...\Adrenaline Sniper Elite V2 Benchmark Tool_is1) (Version:  - )
Aerosoft's - Kastellorizo X - FSX (HKLM\...\Kastellorizo X - FSX) (Version: 1.00 - )
Aerosoft's - Seychelles X - FSX (HKLM\...\Seychelles X - FSX) (Version: 1.00 - Aerosoft)
Aerosoft's - VFR Germany 2 (HKLM\...\{3BB7B4D3-C534-4700-AA1B-B01A8EA5F27C}) (Version: 1.00 - Aerosoft)
Aerosoft's - VFR Germany 3 (HKLM\...\{61C6337D-EDF5-43F0-9E50-541A389070BD}) (Version: 1.00 - Aerosoft)
Aerosoft's - VFR Germany 4 (HKLM\...\{F7016342-C196-44B1-AAC5-D7BA4708473E}) (Version: 1.00 - Aerosoft)
Afterfall InSanity (HKLM\...\{CE9CAAA6-0431-433B-9FB5-23EE01669AF2}) (Version: 1.00.0000 - Nicolas Games S.A.)
Age of Empires II - the Conquerors WideScreen Patcher (HKLM\...\{BA2F3EBC-FE07-4AB5-B906-14DF2C74C523}) (Version: 1.0.40 - Boekabart)
Age of Empires II: HD Edition (HKLM\...\Steam App 221380) (Version:  - )
Age of Empires III - The Asian Dynasties (HKLM\...\InstallShield_{C43C1415-3DFC-4089-9A32-0BECF28A6046}) (Version: 1.00.0000 - Microsoft Game Studios)
Age of Empires III - The Asian Dynasties (Version: 1.00.0000 - Microsoft Game Studios) Hidden
Age of Empires III - The WarChiefs (HKLM\...\InstallShield_{1C08A24C-B168-407E-A826-68FAF5F20710}) (Version: 1.00.0000 - Microsoft Game Studios)
Age of Empires III - The WarChiefs (Version: 1.00.0000 - Microsoft Game Studios) Hidden
Age of Empires III (HKLM\...\InstallShield_{A8CF5C37-8EC5-4C33-BB4A-87F468B77D45}) (Version: 1.00.0000 - Microsoft Game Studios)
Age of Empires III (Version: 1.00.0000 - Microsoft Game Studios) Hidden
Age of Empires Online (HKLM\...\Steam App 105430) (Version:  - Microsoft)
Age of Mythology: Extended Edition (HKLM\...\QWdlb2ZNeXRob2xvZ3lFeHRlbmRlZEVkaXRpb24=_is1) (Version: 1 - )
AIDA64 Engineer v5.00 (HKLM\...\AIDA64 Engineer_is1) (Version: 5.00 - FinalWire Ltd.)
AIMP3 (HKLM\...\AIMP3) (Version: v3.60.1483, 27.02.2015 - AIMP DevTeam)
Airbus Series Vol.2 (FS X) (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Airbus Series Vol.2 (FS X)) (Version:  - )
Alan Wake (HKLM\...\Alan Wake_is1) (Version:  - )
Aliens Colonial Marines Limited Edition DLC Pack Plus Steam Vorbesteller-Bonus 1.0 (HKLM\...\Aliens Colonial Marines Limited Edition DLC Pack Plus Steam Vorbesteller-Bonus 1.0) (Version: 1.0 - .x.X.RIDDICK.X.x.)
Aliens vs Predator Classic 2000 (HKLM\...\1207665883_is1) (Version: 2.0.0.21 - GOG.com)
Aliens vs Predator D3D11 Benchmark V1.03 (HKLM\...\{CC72E6E8-CFFF-43B4-A9BE-C227C088EE95}) (Version: 1.03.0000 - Rebellion)
Aliens: Colonial Marines (HKLM\...\Aliens: Colonial Marines_is1) (Version:  - )
allSnap version 1.33.2 (HKLM\...\allSnap_is1) (Version: 1.33 - Ivan Heckman)
Alone In The Dark (HKLM\...\Alone In The Dark_is1) (Version:  - Atari)
America's Army 3 (HKLM\...\Steam App 13140) (Version:  - U.S. Army)
Amiga Forever (HKLM\...\{DCB8DF8D-6F0E-405B-B870-89709242F5C0}) (Version: 2012.2.0 - Cloanto)
Amnesia: The Dark Descent Demo  (HKLM\...\Steam App 57310) (Version:  - Frictional Games)
Anark Client 1.0 (HKLM\...\AnarkClient) (Version:  - )
AniMake (HKLM\...\AniMake) (Version:  - )
ANNO 1503 GOLD (HKLM\...\{DB833EF9-A198-49BE-970A-BD46F30BFBB4}) (Version: 1.05.00 - )
ANNO 1602 Königs-Edition (HKLM\...\{077A7810-A937-4465-AD08-ACED9807995F}) (Version: 1.00 - )
ANNO 2070 (HKLM\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft)
Anomos 0.9.5 (HKLM\...\Anomos) (Version: 0.9.5 - Anomos Liberty Enhancements)
ArCADia-GRAF 1.5 DE (HKLM\...\{887C98A0-1E31-4C8C-8B72-DA10A860AF71}) (Version: 1.5.6.16 - ArCADiasoft Chudzik sp. j.)
ArCon Professional +2011 (HKLM\...\{7C3C04ED-B746-4273-A0C8-997A8823CB36}) (Version: 15.0.0.0 - Eleco)
ArCon Professional +2011 (Version: 15.0.0.0 - Eleco) Hidden
Arma 3 Complete (HKLM\...\QXJtYTM=_is1) (Version: 1 - )
Assassin's Creed (R) III (HKLM\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.01 - Ubisoft)
Assassin's Creed Brotherhood (HKLM\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Attack Surface Analyzer (HKLM\...\{2710505A-D198-4906-8767-F869909D9FA6}) (Version: 5.3.0.0 - Microsoft Corporation)
Audacity 2.0.6 (HKLM\...\Audacity_is1) (Version: 2.0.6 - Audacity Team)
Auto Gordian Knot 2.55 (HKLM\...\AutoGK) (Version: 2.55 - len0x)
AviSynth 2.5 (HKLM\...\AviSynth) (Version:  - )
AVS Update Manager 1.0 (HKLM\...\AVS Update Manager_is1) (Version:  - Online Media Technologies Ltd.)
AVS Video Converter 7 (HKLM\...\AVS4YOU Video Converter 7_is1) (Version:  - Online Media Technologies Ltd.)
AVS4YOU Software Navigator 1.4 (HKLM\...\AVS4YOU Software Navigator_is1) (Version:  - Online Media Technologies Ltd.)
Baldur's Gate II (HKLM\...\Baldur's Gate II_is1) (Version:  - GOG.com)
Bandicam (HKLM\...\Bandicam) (Version: 2.1.2.740 - Bandisoft.com)
Bandisoft MPEG-1 Decoder (HKLM\...\BandiMPEG1) (Version:  - Bandisoft.com)
Baphomets Fluch - Der schlafende Drache (HKLM\...\Baphomets Fluch - Der schlafende Drache) (Version:  - )
Batman: Arkham City Digital Deluxe Edition (HKLM\...\{E8AC6BBD-9A99-404C-9638-F633312CD441}_is1) (Version: 1.0 - RAF)
Battle Realms Complete (HKLM\...\Battle Realms Complete_is1) (Version:  - GOG.com)
Battlefield 3™ (HKLM\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlefield Heroes (HKLM\...\{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}) (Version:  - EA Digital illusions)
Bejeweled® 3 (HKLM\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.)
Beneath a Steel Sky (HKLM\...\GOGPACKBENEATH_is1) (Version: 2.0.0.9 - GOG.com)
Bewerbungs-Experte 2011 (HKLM\...\Bewerbungs-Experte_is1) (Version: 3.0.0.0 - haude electronica verlag)
Binary Domain (HKLM\...\Binary Domain_is1) (Version:  - )
BioShock 2 (HKLM\...\{4A8B461A-9336-4CF9-98F4-14DD38E673F0}) (Version: 1.00.0000 - 2K Games)
BioShock Infinite (HKLM\...\BioShock Infinite_is1) (Version:  - )
Blade Runner (HKLM\...\Blade Runner) (Version: 1.05 -  Westwood Studios 1997)
Blender (HKLM\...\Blender) (Version: 2.69 - Blender Foundation)
Brutal Legend version 1 (HKLM\...\QnJ1dGFsIExlZ2VuZA==_is1) (Version: 1 - )
Bulletstorm (HKLM\...\GFWL_{45410935-3E72-472B-8C35-AB1000008200}) (Version: 1.0.0000.130 - EA)
Bulletstorm (Version: 1.0.0000.130 - EA) Hidden
Burnout(TM) Paradise The Ultimate Box (HKLM\...\{9A996B6A-846E-4A89-B9C4-17546B7BE49F}) (Version: 1.0.0.0 - Electronic Arts)
C&C Der Tiberiumkonflikt (HKLM\...\C&C Der Tiberiumkonflikt_is1) (Version:  - )
Cain & Abel 4.9.56 (HKLM\...\Cain & Abel 4.9.56) (Version:  - )
calibre (HKLM\...\{0CF3C0FA-02EA-4E15-9495-1C441C0377B3}) (Version: 2.18.0 - Kovid Goyal)
Call of Duty Black Ops GERMAN Uncut 1.00 (HKLM\...\Call of Duty Black Ops GERMAN Uncut 1.00) (Version:  - )
Call of Duty Modern Warfare 3 (c) Activision version 1 (HKLM\...\Call of Duty Modern Warfare 3 (c) Activision_is1) (Version: 1 - )
Call of Duty: Black Ops II v1.0 (HKLM\...\{26B8A445-02C6-4F87-AD2A-024BBFC99A06}_is1) (Version: 1.0 - RAF)
Cannon Fodder (HKLM\...\GOGPACKCANNONFODDER_is1) (Version: 2.0.0.3 - GOG.com)
Capitalism 2 (HKLM\...\GOGPACKCAPITALISM2_is1) (Version: 2.0.0.5 - GOG.com)
Castle of Illusion (HKLM\...\Q2FzdGxlb2ZJbGx1c2lvbg==_is1) (Version: 1 - )
Castlevania Lords of Shadow (HKLM\...\{F14EDCE5-B45D-4D77-A5B8-C7513E5C7BDA}) (Version: 6.0 - Black Box)
CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5143 - CDBurnerXP)
CDex - Open Source Digital Audio CD Extractor (HKLM\...\CDex) (Version: 1.72.1.2014 - Georgy Berdyshev)
Chaos auf Deponia Demo (HKLM\...\Deponia 2 Demo) (Version: 1.0 - Daedalic Entertainment)
Cheat Engine 6.2 (HKLM\...\Cheat Engine 6.2_is1) (Version:  - Dark Byte)
Cheatbook Database 2014 (HKLM\...\Cheatbook Database 2014) (Version:  - )
ClamWin Free Antivirus 0.98.4.1 (HKLM\...\ClamWin Free Antivirus_is1) (Version:  - alch)
ClassicPro© v2.01 (HKLM\...\ClassicPro) (Version: 2.01 - Skin Consortium)
ClearProg 1.6.1 Beta 8 (HKLM\...\ClearProg) (Version: 1.6.1 Beta 8 - Sven Hoffman)
CLICKBIOSII (HKLM\...\{EBCB111F-4907-4B28-BD03-F5BD901106D2}_is1) (Version: 1.0.123 - MSI)
Colin McRae Rally Remastered (HKLM\...\Colin McRae Rally Remastered_is1) (Version:  - )
Command & Conquer 3 (HKLM\...\{B0C30E93-D3D9-4F04-A2AC-54749B573275}) (Version: 1.00.0000 - Ihr Firmenname)
Command & Conquer Alarmstufe Rot 2 (HKLM\...\Red Alert 2) (Version:  - )
Command & Conquer Generals (HKLM\...\InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}) (Version: 0.50.0000 - Electronic Arts)
Command & Conquer Generals (Version: 0.50.0000 - Electronic Arts) Hidden
Command & Conquer Teil 3: Operation Tiberian Sun (HKLM\...\Tiberian Sun) (Version:  - )
Command & Conquer™ 3: Kanes Rache (HKLM\...\{CC2422C9-F7B5-4175-B295-5EC2283AA674}) (Version: 1.00.0000 - Ihr Firmenname)
Command & Conquer™ 4 Tiberian Twilight (HKLM\...\{82696435-8572-4D8B-A230-D1AA567D0F0F}) (Version: 1.0.0.0 - Electronic Arts)
Command & Conquer™ Alarmstufe Rot 3 (HKLM\...\{296D8550-CB06-48E4-9A8B-E5034FB64715}) (Version: 1.0.1.0 - Electronic Arts)
Command & Conquer™ Alarmstufe Rot 3 Der Aufstand (HKLM\...\{DDE59617-F59A-473B-BC4E-C2B81F6CD38D}) (Version: 1.0.1.0 - Electronic Arts)
Command && Conquer Alarmstufe Rot 2 - Yuris Rache (HKLM\...\Yuri's Revenge) (Version:  - )
Command and Conquer(TM) Generäle Die Stunde Null  (HKLM\...\InstallShield_{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}) (Version: 1.00.0000 - Electronic Arts)
Command and Conquer(TM) Generäle Die Stunde Null  (Version: 1.00.0000 - Electronic Arts) Hidden
Commando (HKLM\...\ComandoDeinstKey) (Version:  - )
Commandos 2: Men of Courage (HKLM\...\{F7963BA0-EE1C-11D4-9FA5-00A0C9E6A342}) (Version:  - )
Commandos 3 - Destination Berlin (HKLM\...\{C270BC04-1540-4673-960F-A546B2C860CD}) (Version:  - )
ConvertAll (HKLM\...\ConvertAll) (Version:  - )
Corel Graphics - Windows Shell Extension (HKLM\...\_{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}) (Version: 15.2.0.686 - Corel Corporation)
Corel Graphics - Windows Shell Extension (Version: 15.2.686 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Common (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Connect (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Custom Data (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - DE (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Draw (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - EN (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - ES (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Extra Content (HKLM\...\_{5A10CFDA-FA2B-453C-B561-AE864E62EAC8}) (Version:  - Corel Corporation)
CorelDRAW Essentials X5 - Extra Content (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Filters (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - FR (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - IPM (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - IT (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - PHOTO-PAINT (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Redist (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Setup Files (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - WT (Version: 15.3 -  Corel Corporation) Hidden
CorelDRAW Essentials X5 (HKLM\...\_{EDBEBF07-F880-48FB-9AA5-0E8E71E02D83}) (Version: 15.2.0.686 - Corel Corporation)
CorelDRAW Essentials X5 (Version: 15.3 - Corel Corporation) Hidden
Counter-Strike Nexon: Zombies (HKLM\...\Steam App 273110) (Version:  - Nexon)
Counter-Strike: Global Offensive - SDK (HKLM\...\Steam App 745) (Version:  - )
Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version:  - Valve)
CPUID CPU-Z 1.72 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Crysis® 2 (HKLM\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.0.0.0 - Electronic Arts)
Crysis®3 (HKLM\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.1.0.0 - Electronic Arts)
CrystalDiskMark 3.0.3a (HKLM\...\CrystalDiskMark_is1) (Version: 3.0.3a - Crystal Dew World)
CyberLink PowerDVD 11 (HKLM\...\InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}) (Version: 11.0.1620.51 - CyberLink Corp.)
Dark Souls Prepare to Die Edition (HKLM\...\GFWL_{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.)
Dark Souls Prepare to Die Edition (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
Darksiders 1.1(CREATED BY XEONKING©) (HKLM\...\Darksiders_is1) (Version: 1.1 - )
Das Haus am See - Kinder der Stille Sammleredition 1.0.0.0 (HKLM\...\Das Haus am See - Kinder der Stille Sammleredition 1.0.0.0) (Version: 1.0.0.0 - Shadow - Time to play)
Das Telefonbuch Deutschland (HKLM\...\DasTelefonbuch Deutschland) (Version:  - TVG Telefonbuch- und Verzeichnisverlag GmbH & Co. KG)
Datennetzwerktechnik (HKLM\...\Datennetzwerktechnik) (Version:  - )
Dead Island Riptide (c) Deep Silver version 1 (HKLM\...\RGVhZCBJc2xhbmQgUmlwdGlkZSAoYykgRGVlcCBTaWx2ZXI=_is1) (Version: 1 - )
Dead Space (HKLM\...\{025A585C-0C66-413D-80D2-4C05CB699771}) (Version: 1.0.0.222 - Electronic Arts)
Dead Space™ 2 (HKLM\...\{96D06FDD-6AF4-4309-BC1B-1C9588B0575E}) (Version: 1.0.941.0 - Electronic Arts)
Delta Force (HKLM\...\Delta Force) (Version:  - )
Delta Force 2 (HKLM\...\Delta Force 2) (Version:  - )
Descent and Descent 2 (HKLM\...\Descent and Descent 2_is1) (Version:  - GOG.com)
DesignSpark Mechanical 2.0 (HKLM\...\{ADF11148-6555-FFFF-A320-274AF0C42282}) (Version: 10.0.0 - SpaceClaim Corporation)
Deus EX Human Revolution Version v1.1 (HKLM\...\{2DDC57D4-594D-4F30-8D81-27FDB2243644}_is1) (Version: v1.1 - ZKY)
D-Fend Reloaded 1.3.6 (deinstallieren) (HKLM\...\D-Fend Reloaded) (Version: 1.3.6 - Alexander Herzog)
Dia (nur entfernen) (HKLM\...\Dia) (Version:  - )
Die Siedler II - Die nächste Generation (HKLM\...\S2TNG) (Version:  - )
Die Sims™ 3 (HKLM\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.9.22 - Electronic Arts)
D-Info mit Rückwärtssuche Frühjahr 2012 (HKLM\...\{36F8E574-A5D0-425C-AF52-FFA2D4616ED6}) (Version: 1.00.0000 - telegate MEDIA AG)
DirSync  2.96 (HKLM\...\DirSync) (Version:  - Stephen Kalisch)
DiRT 3 (HKLM\...\GFWL_{434D0FA0-1558-4D8E-AC3D-BD1000008200}) (Version: 1.0.0000.130 - Codemasters)
DiRT 3 (Version: 1.0.0000.130 - Codemasters) Hidden
DLH98 v1.44 (HKLM\...\DLH98) (Version:  - )
Doc Scrubber v1.1 (HKLM\...\Doc Scrubber_is1) (Version: 1.1 - Javacool Software LLC)
Dolphin x86 (HKLM\...\Dolphin x86) (Version: 4.0.2 - Dolphin Development Team)
Doom 3: BFG Edition (HKLM\...\{2EBA122F-BB93-4FCF-ACC3-59374E7CF3C9}_is1) (Version: 1.0 - RAF)
Dr_Brain_GJ_Vol2 (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Dr_Brain_GJ_Vol2) (Version:  - )
Dracula Origin (HKLM\...\Dracula Origin_is1) (Version:  - )
Duke Nukem Forever DELUXE EDITION incl. dem DLC The Doctor Who Cloned Me 1.01 (HKLM\...\Duke Nukem Forever DELUXE EDITION incl. dem DLC The Doctor Who Cloned Me 1.01) (Version:  - )
DVD Identifier (HKLM\...\DVD Identifier_is1) (Version: 5.2.0 - Kris Schoofs)
DVD-lab PRO 2.0 (HKLM\...\DVD-lab PRO 2.0 deutsch_is1) (Version:  - )
Earthworm Jim 3D (HKLM\...\Earthworm Jim 3D_is1) (Version:  - GOG.com)
EAX Unified (HKLM\...\EAX Unified) (Version:  - )
Elektronik 2 V2.0 (HKLM\...\Elektronik 2 V2.0) (Version:  - )
eLicenser Control (HKLM\...\eLicenser Control) (Version:  - Steinberg Media Technologies GmbH)
EMET 5.1 (HKLM\...\{72E7AE20-5B12-4F27-AF5E-DA03E3C09466}) (Version: 5.1 - Microsoft Corporation)
Emsisoft HiJackFree 4.5 (HKLM\...\Emsisoft HiJackFree_is1) (Version: 4.5 - Emsisoft GmbH)
Enclave (HKLM\...\Steam App 253980) (Version:  - Topware)
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
EVEREST Ultimate Edition v5.30 (HKLM\...\EVEREST Ultimate Edition_is1) (Version: 5.30 - Lavalys, Inc.)
Everything 1.3.4.686 (x86) (HKLM\...\Everything) (Version:  - )
Far Cry 3 (HKLM\...\{3E7F5A51-7657-43D6-A9B3-C3A21473834B}_is1) (Version: 1.01 - RAF)
FEZ (HKLM\...\FEZ_is1) (Version:  - Trapdoor)
FIFA 14 Version 1.0 u1 (HKLM\...\FIFA 14_is1) (Version: 1.0 u1 - EA Games)
FileZilla Client 3.10.2 (HKLM\...\FileZilla Client) (Version: 3.10.2 - Tim Kosse)
Fischer Weltalmanach und Atlas 2012 (HKLM\...\InstallShield_{8B1B9DF1-DB57-4A69-8047-D64C0F46ADA7}) (Version: 1.00.0000 - USM)
Fischer Weltalmanach und Atlas 2012 (Version: 1.00.0000 - USM) Hidden
FixFoto 3.00 (HKLM\...\FixFoto_is1) (Version:  - Joachim Koopmann Software)
Flash Drive Tester v1.14 (HKLM\...\{272C8DEE-F54F-406C-9AA6-B4DE2985A47C}) (Version: 1.14 - Virtual Console)
Fraps (remove only) (HKLM\...\Fraps) (Version:  - )
FreeFileSync 6.13 (HKLM\...\FreeFileSync_is1) (Version: 6.13 - www.FreeFileSync.org)
FUEL (HKLM\...\{F51FF206-2273-4B3E-A90A-4752AE288C12}) (Version: 1.00.0000 - Codemasters)
Futuremark SystemInfo (HKLM\...\{A7E0E8D0-2E06-428A-8A8A-83BFF0B4DFE6}) (Version: 4.34.498.0 - Futuremark)
Gabelstapler 2014 1.0.2 (HKLM\...\{9B9000F2-DD0C-40AA-9ED6-6776B83894E1}_is1) (Version:  - UIG Entertainment)
Gabriel Knight - Sins of the Fathers Demo (HKLM\...\Steam App 318170) (Version:  - Phoenix Online Studios)
GALCOM Echo Squad SE Demo Docs (HKLM\...\GALCOM Echo Squad SE Demo Docs) (Version:  - 3000AD, Inc.)
Game Compatibility Database (HKLM\...\{0e82bf4c-b906-4635-a97e-6a9740686b33}.sdb) (Version:  - )
Gameforge Live 2.0.6 (HKLM\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.6 - Gameforge)
Gas Guzzlers Combat Carnage (HKLM\...\Gas Guzzlers Combat Carnage_is1) (Version:  - )
gbrainy 2.06 (HKLM\...\gbrainy) (Version: 2.06 - )
GCFScape 1.8.4 (HKLM\...\GCFScape_is1) (Version:  - Ryan Gregg)
Gears of War (HKLM\...\InstallShield_{1170D24F-42B7-40CF-AA1B-6395CE562354}) (Version: 1.00.0000 - Microsoft Game Studios)
Gears of War (Version: 1.00.0000 - Microsoft Game Studios) Hidden
Geeks3D PhysX FluidMark v1.5.2 (HKLM\...\{0B7C79A5-5CB2-4ABD-A9C1-92A6213CE8DD}_is1) (Version:  - Geeks3D.com)
Geeks3D.com FurMark 1.10.1 (HKLM\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version:  - Geeks3D.com)
Gehirnjogging - Generations (HKLM\...\CD_Gehirnjogging_Generations_DE) (Version:  - )
Gehirnjogging 4 (HKLM\...\Gehirnjogging 4) (Version: 1.0 - SBT)
Gemeinsam genutzte Internet-Komponenten von Westwood (HKLM\...\WOLAPI) (Version:  - )
GetRight (HKLM\...\GetRight_is1) (Version:  - Headlight Software, Inc.)
Gods Will Be Watching (HKLM\...\1207664883_is1) (Version: 2.0.0.1 - GOG.com)
GoldWave v5.66 (HKLM\...\GoldWave v5.66) (Version:  - )
Goodbye Deponia Demo (HKLM\...\Steam App 262880) (Version:  - Daedalic Entertainment)
Google Earth Pro (HKLM\...\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
GPS-Track-Analyse.NET 6.0 (HKLM\...\GPS-Track-Analyse.NET 6.0_is1) (Version:  - )
Grand Theft Auto IV (HKLM\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (Version: 1.0.0011.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV (Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
GRID Autosport (HKLM\...\GRID Autosport_is1) (Version: GRID Autosport - )
GSAK 8.4.0.0 (HKLM\...\GSAK_is1) (Version:  - CWE computer services)
GTA IV Vehicle Mod Installer v1.2 (HKLM\...\GTA IV Vehicle Mod Installer v1.2_is1) (Version:  - MobileD2)
Gunpoint Demo (HKLM\...\Steam App 240570) (Version:  - )
Half-Life Singleplayer Edition (HKLM\...\{D2FEF059-3942-4E50-B825-4E208DBC63F2}_is1) (Version: 1.1.2010 - Valve)
HashTab 5.2.0.14 (HKLM\...\HashTab) (Version: 5.2.0.14 - Implbits Software)
Haunted Past - Im Reich der Geister 1.00 (HKLM\...\Haunted Past - Im Reich der Geister 1.00) (Version:  - )
HD Tune Pro 5.00 (HKLM\...\HD Tune Pro_is1) (Version:  - EFD Software)
Heaven Benchmark version 4.0 (HKLM\...\Unigine Heaven Benchmark (Basic Edition)_is1) (Version: 4.0 - Unigine Corp.)
Heaven DX11 Benchmark version 3.0 (HKLM\...\Unigine Heaven DX11 Benchmark (Basic Edition)_is1) (Version: 3.0 - Unigine Corp.)
HijackThis 2.0.2 (HKLM\...\HijackThis) (Version: 2.0.2 - TrendMicro)
Hitman Absolution (HKLM\...\Hitman Absolution_is1) (Version:  - )
Homebrew - Vehicle Sandbox Demo (HKLM\...\Steam App 327770) (Version:  - Copybugpaste)
Homefront (HKLM\...\Homefront_is1) (Version:  - )
HWiNFO32 Version 4.42 (HKLM\...\HWiNFO32_is1) (Version: 4.42 - Martin Malík - REALiX)
HyperSnap 6 (HKLM\...\HyperSnap 6) (Version: 6.70.02 - Hyperionics Technology LLC)
IconPackager (HKLM\...\IconPackager) (Version: 5.10.032 - Stardock Corporation)
IconPackager (Version: 5.10.032 - Stardock Corporation) Hidden
ImgBurn (HKLM\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
Incredipede (HKLM\...\GOGPACKINCREDIPEDE_is1) (Version: 2.0.0.4 - GOG.com)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.8.251 - Intel Corporation)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.35 - Irfan Skiljan)
IsoBuster 3.5 (HKLM\...\IsoBuster_is1) (Version: 3.5 - Smart Projects)
IT-Sicherheit (HKLM\...\IT-Sicherheit) (Version:  - )
Jagged Alliance (HKLM\...\Jagged Alliance_is1) (Version:  - GOG.com)
Jagged Alliance 2 (HKLM\...\Jagged Alliance 2_is1) (Version:  - GOG.com)
Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Java 8 Update 40 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
JonDo (HKLM\...\JonDoUninstall) (Version:  - )
jStrip 3.3 (HKLM\...\jStrip_is1) (Version: 3.3 - David Crowell)
Kalenderchen 5 (HKLM\...\{11464943-4682-4F6B-A96D-D4E8C26DD111}_is1) (Version:  - Daniel Manger)
KaloMa 4.92 (HKLM\...\KaloMa_is1) (Version:  - Frank Böpple)
KeePass Password Safe 2.27 (HKLM\...\KeePassPasswordSafe2_is1) (Version: 2.27 - Dominik Reichl)
Kingdoms of Amalur: Reckoning (HKLM\...\{6A9D1594-7791-48f5-9CAA-DE9BCB968320}) (Version: 1.0.0.0 - Electronic Arts)
KKND Krossfire (HKLM\...\KKND Krossfire) (Version:  - )
K-Lite Codec Pack 11.0.0 Full (HKLM\...\KLiteCodecPack_is1) (Version: 11.0.0 - )
K-Meleon 74.0 (x86 en-US) (HKLM\...\K-Meleon 74.0 (x86 en-US)) (Version: 74.0 - kmeleonbrowser.org)
Knights and Merchants (HKLM\...\Steam App 253900) (Version:  - Topware Interactive)
Kolor Autopano Giga 3.6 (HKLM\...\AutopanoGiga3.6) (Version: V3.6.3 - Kolor)
Lara Croft and the Guardian of Light (HKLM\...\Lara Croft and the Guardian of Light_is1) (Version:  - )
LauschAngriff (HKLM\...\LauschAngriff) (Version:  - )
LEGO - The Hobbit (HKLM\...\TEVHT1RoZUhvYmJpdA==_is1) (Version: 1 - )
LEGO Batman 3 - Beyond Gotham (HKLM\...\TEVHT0JhdG1hbjNCZXlvbmRHb3RoYW0=_is1) (Version: 1 - )
LEGO Digital Designer (HKLM\...\New LEGO Digital Designer) (Version:  - LEGO A/S)
LEGO MARVEL Super Heroes (HKLM\...\LEGO MARVEL Super Heroes_is1) (Version:  - Warner Bros. Games)
LEGO® Batman™ (HKLM\...\InstallShield_{398AB469-77FC-4935-820B-D419388C0A6A}) (Version: 1.00.0000 - Warner Bros. Interactive Entertainment)
LEGO® Batman™ (Version: 1.00.0000 - Warner Bros. Interactive Entertainment) Hidden
LEGO® Der Herr der Ringe™ (HKLM\...\{C6F20FA7-342A-47A9-A3C8-EB36CABE6419}) (Version: 1.0.0.0 - Warner Bros. Interactive Entertainment)
LEGO® Pirates of the Caribbean Das Videospiel (HKLM\...\{64958DA4-79D3-43FD-AF06-720DAD044F9E}) (Version: 1.0.0.0 - Disney Interactive Studios)
Leistungselektronik (HKLM\...\Leistungselektronik) (Version:  - )
Life Goes On Demo (HKLM\...\Steam App 246380) (Version:  - )
Lightworks (HKLM\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 12.0.2.0 - Lightworks)
Logitech Gaming Software 5.10 (HKLM\...\{60D32CDC-E3BE-4578-BA10-29322307CDDC}) (Version: 5.10.127 - Logitech)
LOST PLANET 2 (HKLM\...\{737369DC-08E8-4787-A78C-F86943247BDF}) (Version: 1.0.0.129 - CAPCOM CO., LTD.)
MadOnion.com/3DMark2000 (HKLM\...\MadOnion.com/3DMark2000) (Version:  - )
MadOnion.com/3DMark2001 SE (HKLM\...\{91B323B5-A79C-4D23-BD6D-046C565F9BCF}) (Version:  - )
Magic Games II (HKLM\...\{AB38070F-5479-4F76-8419-80A758B7B16B}) (Version: 1.0.0 - magicn)
Magic The Gathering - Duels of the Planeswalkers (HKLM\...\Magic The Gathering - Duels of the Planeswalkers_is1) (Version:  - )
Magical Jelly Bean KeyFinder (HKLM\...\KeyFinder_is1) (Version: 2.0.9.8 - Magical Jelly Bean)
MahJong Suite 2011 v8.2 (HKLM\...\MahJong Suite_is1) (Version:  - TreeCardGames)
Majesty 2: The Fantasy Kingdom Sim (HKLM\...\{CDCA3C32-FCE7-40E8-8CB5-7B0E87ADDFC9}_is1) (Version: 1.0.0.0 - Paradox Interactive)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Mandelbulber (HKLM\...\35A39AB0-5E9F-4B70-98DA-4B8158C89C4B) (Version: 1.21-1 - )
Maniac Mansion Deluxe (HKLM\...\Maniac Mansion Deluxe) (Version:  - )
Medal of Honor™ Warfighter Deutsch Patch 1.00 (HKLM\...\Medal of Honor™ Warfighter Deutsch Patch 1.00) (Version:  - )
MediaCoder 0.8.30.5622 (HKLM\...\MediaCoder) (Version: 0.8.30.5622 - Mediatronic)
Memoria Demo (HKLM\...\Steam App 250940) (Version:  - Daedalic Entertainment)
Metro Last Light Update 12 (v1.0.0.14) Plus limited First Edition DLCs Plus Chronicles Pack DLC v1.0.0.14 (HKLM\...\Metro Last Light Update 12 (v1.0.0.14) Plus limited First Edition DLCs Plus Chronicles Pack DLC v1.0.0.14) (Version:  - )
Metro: Last Light (c) Deep Silver version 1 (HKLM\...\TWV0cm9MYXN0TGlnaHQ=_is1) (Version: 1 - )
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Age of Empires Gold (HKLM\...\Age of Empires Gold 1.0) (Version:  - )
Microsoft Age of Empires II (HKLM\...\Age of Empires 2.0) (Version:  - )
Microsoft Age of Empires II: The Conquerors Expansion (HKLM\...\Age of Empires II: The Conquerors Expansion 1.0) (Version:  - )
Microsoft Baseline Security Analyzer 2.3 (HKLM\...\{C3013E88-B772-4446-A0AE-A7F37180B9F1}) (Version: 2.3.2208 - Microsoft Corporation)
Microsoft Flight Simulator X Service Pack 2 (HKLM\...\{E7CC4B85-DC2F-463F-8FEB-E7398E25C19A}) (Version: 10.0.61472.0 - Microsoft Game Studios)
Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Image Composite Editor (HKLM\...\{3D599ADA-65D9-4B51-898F-CE718DEC5DBB}) (Version: 1.4.4 - Microsoft Corporation)
Microsoft Keyboard Layout Creator 1.4 (HKLM\...\{99E66BC9-E4B6-485F-ABFC-31EFCE36DFDF}) (Version: 1.4.6000 - Microsoft Corp.)
Microsoft LifeCam (HKLM\...\{BD71B413-9FEE-49BB-A6D1-2C0BFB99BDFE}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{485DE620-A598-4481-ACDC-61734504DB74}) (Version: 11.0.2318.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{09298F26-A95C-31E2-9D95-2C60F586F075}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Windows Performance Toolkit (HKLM\...\{E7F9E526-2324-437B-A609-E8C5309465CB}) (Version: 4.8.0 - Microsoft Corporation)
Microsoft Windows SDK for Windows 7 (7.1) (HKLM\...\SDKSetup_7.1.7600.0.30514) (Version: 7.1.7600.0.30514 - Microsoft Corporation)
Microsoft WorldWide Telescope (HKLM\...\{7785F029-FBFF-4572-8E1C-596D8A28B548}) (Version: 5.1.09 - Microsoft Research)
Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{AC4C38FD-A54C-4CA5-92EE-D983CD81293E}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Midori 0.5.9 (HKLM\...\Midori) (Version: 0.5.9 - Christian Dywan)
Mind Path to Thalamus (HKLM\...\Mind Path to Thalamus_is1) (Version:  - )
Minecraft1.7.9 (HKLM\...\Minecraft1.7.9) (Version:  - )
MiniTool Partition Wizard Home Edition 8.1.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
mirkes.de Tiny Hexer (HKLM\...\{CC399A03-4695-432E-AE6E-BB450DDE5248}_is1) (Version: 1.8 - markus stephany)
Mirror's Edge™ (HKLM\...\{AEDBD563-24BB-4EE3-8366-A654DAC2D988}) (Version: 1.0.0.0 - Electronic Arts)
Monitor Calibration Wizard 1.0 (HKLM\...\Monitor Calibration Wizard) (Version:  - )
Monkey Island™ Special Edition Collection (HKLM\...\MISEC) (Version: 1.0.0.0 - LucasArts)
MonochromiX 1.39 (HKLM\...\MonochromiX_is1) (Version:  - Joachim Koopmann Software)
Monopoly (HKLM\...\{D7E7EC5E-4349-4E40-B37C-4342188B86EC}) (Version:  - )
Moo0 System Monitor 1.76 (HKLM\...\Moo0 SystemMonitor) (Version:  - )
Moorhuhn Remake (HKLM\...\{52210D57-0B1F-4681-90DD-8659DF4BCC40}) (Version: 1.00.0000 - )
MozBackup 1.5.1 (HKLM\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 36.0.4 (x86 de) (HKLM\...\Mozilla Firefox 36.0.4 (x86 de)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MPU (HKLM\...\{18F6D695-66FF-411C-9347-55D1140A7D7B}) (Version: 1.1.8 - Hergarten Media)
MSI Afterburner 4.0.0 (HKLM\...\Afterburner) (Version: 4.0.0 - MSI Co., LTD)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser und SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
MyFFVideoConverter (HKLM\...\MyFFVideoConverter) (Version: 1.0.0.0 - Pergel.hu)
NASA World Wind 1.4 (HKLM\...\NASA World Wind 1.4) (Version:  - )
NASAEyes (HKLM\...\{3E9B108D-9985-4043-B0B0-29F29221C9A6}) (Version: 1.0.0.0 - JPL/NASA-Caltech)
Native Instruments Traktor DJ Studio 3 (HKLM\...\Native Instruments Traktor DJ Studio 3) (Version:  - )
Need for Speed™ ProStreet (HKLM\...\{2E1A71D5-7897-4F3F-B0E3-B412C86A646D}) (Version: 1.0.1.0 - Electronic Arts)
Need for Speed™ Rivals (HKLM\...\{E0A32336-AA27-4053-99B2-C3380B7B95AC}) (Version: 1.3.0.0 - Electronic Arts)
Need For Speed™ World (HKLM\...\{3AF1B16A-7DC9-4C80-BAEC-70B088A7C5B8}) (Version: 1.0.0.0 - Electronic Arts)
Nemeth Designs Bell UH-1 Huey for Microsoft Flight Simulator X (HKLM\...\Nemeth Designs Bell UH-1 Huey for Microsoft Flight Simulator X) (Version:  - )
NetLimiter 3 (HKLM\...\{913923AB-3AAB-4870-8910-627C4CD82789}) (Version: 3.0.0.11 - Locktime Software s.r.o.)
NetSetMan 3.7.3 (HKLM\...\NetSetMan_is1) (Version: 3.7.3 - Ilja Herlein)
NetSpeedMonitor 2.5.4.0 x86 (HKLM\...\{86501894-E722-4385-A792-B7C2F28FAE7B}) (Version: 2.5.4.0 - Florian Gilles)
NetTools 5.0 (HKLM\...\NetTools_is1) (Version: 5.0 - Mohammad Ahmadi Bidakhvidi)
NexusFont 2.5 (ver 2.5.8.1582) (HKLM\...\{EFEDD205-43FE-4208-B682-0937E803E19E}_is1) (Version:  - xiles)
NNScript (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\NoNameScript) (Version: 4.22 - ESNation)
Notepad++ (HKLM\...\Notepad++) (Version: 6.5.3 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 347.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 347.09 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.52 - NVIDIA Corporation)
NVIDIA Alien vs. Triangles demo (HKLM\...\Alien vs. Triangles) (Version: 1.0 - NVIDIA Corporation)
NVIDIA FaceWorks: Real-time Performance Capture Demo (HKLM\...\FaceWorks) (Version: 1.0 - NVIDIA Corporation)
NVIDIA Grafiktreiber 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.52 - NVIDIA Corporation)
NVIDIA Hair Demo (HKLM\...\{BF2D55FB-975E-4B59-9C10-439A975701FF}) (Version: 1.00 - )
NVIDIA HD-Audiotreiber 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
NVIDIA Screen Saver 1.2 (HKLM\...\NVIDIA Screen Saver_is1) (Version:  - )
NVIDIA Supersonic Sled demo (HKLM\...\Supersonic Sled) (Version:  - )
O&O Defrag Professional (HKLM\...\{24CD85A3-6562-4C24-8257-27826C7CF7FE}) (Version: 15.8.813 - O&O Software GmbH)
O&O SafeErase Professional (HKLM\...\{4649998A-0D48-45C2-AF5B-FBD5ECF536ED}) (Version: 5.1.636 - O&O Software GmbH)
O&O UnErase (HKLM\...\{37F6190F-8A86-4B19-86A3-5A59BEA62823}) (Version: 6.0.1899 - O&O Software GmbH)
OMSI - Der Omnibussimulator (HKLM\...\{9AE850A4-B89D-4875-A159-B1B64D717EFB}) (Version: 1.06 - aerosoft)
OpenAL (HKLM\...\OpenAL) (Version:  - )
OpenVPN 2.3.4-I603  (HKLM\...\OpenVPN) (Version: 2.3.4-I603 - )
Opera 12.17 (HKLM\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
Oracle VM VirtualBox 4.3.26 (HKLM\...\{26B8608D-6C29-4171-9751-67621C834AA3}) (Version: 4.3.26 - Oracle Corporation)
Orcs Must Die 2 - Language Addon (HKLM\...\Orcs Must Die 2_is1) (Version:  - )
Orcs Must Die! Unchained (HKLM\...\{8EBA33AF-48E0-4207-A4EE-96029415AD76}_is1) (Version:  - Gameforge 4D GmbH)
Origin (HKLM\...\Origin) (Version: 9.1.11.2678 - Electronic Arts, Inc.)
PA38 Tomahawk FSX/P3D (HKLM\...\PA38 Tomahawk FSX/P3D) (Version: 1.00.00.00 - ALABEO)
PAC-MAN Championship Edition DX+ Demo (HKLM\...\Steam App 247260) (Version:  - Mine Loader Software Co., Ltd.)
Painkiller Hell and Damnation (HKLM\...\Painkiller Hell and Damnation_is1) (Version:  - )
Paragon ExtFS for Windows (HKLM\...\ParagonExtFS) (Version:  - )
Paragon Hard Disk Manager™ 14 Suite (HKLM\...\{29258311-EA49-11DE-967C-005056C00008}) (Version: 90.00.0003 - Paragon Software)
Path of Exile (HKLM\...\Steam App 238960) (Version:  - Grinding Gear Games)
Pazera Free Audio Extractor 1.4 (HKLM\...\{6899C238-3E4A-4A04-B251-A0C9EDC7EDBC}_is1) (Version: 1.4 - Pazera Jacek)
PC Tune-Up (Version: 2.2.0.1 - ZoneAlarm) Hidden
PCMark 7 (HKLM\...\{75C3C9C0-6CE6-42FA-A0E9-658E8F539124}) (Version: 1.4.0 - Futuremark)
PCSX2 - Playstation 2 Emulator (HKLM\...\pcsx2-r5875) (Version:  - )
PDF Settings CS5 (Version: 10.0 - Adobe Systems Incorporated) Hidden
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.311.0 - Tracker Software Products Ltd)
PeerBlock 1.2 (r693) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.2.0.693 - PeerBlock, LLC)
PeerGuardian 2.0 (HKLM\...\PeerGuardian_is1) (Version: 2.0.6.4 - Methlabs Productions)
Pluto Client (HKLM\...\{F8584160-CC6E-11d5-954F-5254AB1A4DB7}) (Version:  - )
Portal 2 Version 1.0 u23 (HKLM\...\Portal 2_is1) (Version: 1.0 u23 - Valve)
Portrait Professional Studio 9.8 (HKLM\...\PortraitProfessionalStudio9_is1) (Version: 9.8 - Anthropics Technology Ltd.)
Pro Evolution Soccer 2014 - World Challenge (HKLM\...\Pro Evolution Soccer 2014 - World Challenge_is1) (Version:  - )
Pro Evolution Soccer 2015 Demo (HKLM\...\Steam App 321280) (Version:  - KONAMI Digital Entertainment)
Prototype 2 (HKLM\...\Prototype 2_is1) (Version:  - )
Prototype(TM) (HKLM\...\InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}) (Version: 1.0 - Activision)
Prototype(TM) (Version: 1.0 - Activision) Hidden
Puppet Show 5 - Ungewisses Schicksal Sammleredition (HKLM\...\Puppet Show 5 - Ungewisses Schicksal Sammleredition 1.0) (Version: 1.0 - Dok)
Quake (HKLM\...\Quake_is1) (Version:  - )
Quake 4 1.4.2 (HKLM\...\Quake 4 1.4.2) (Version:  - )
Quake III Arena (HKLM\...\Quake III Arena) (Version:  - )
Quest for Infamy  (HKLM\...\Quest for Infamy) (Version:  - Infamous Quests)
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Rage Complete Edition MULTi-9 1.3 (HKLM\...\Rage Complete Edition MULTi-9 1.3) (Version:  - )
Railworks 3 Train Simulator 2012 Deluxe (HKLM\...\Railworks 3 Train Simulator 2012 Deluxe_is1) (Version:  - )
RamDisk Plus 11.6 (HKLM\...\{D96E4F17-2635-4CBD-9308-F99228929C41}) (Version: 11.6.795 - SuperSpeed LLC)
Rapture3D 2.4.8 Game (HKLM\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
Ravensburger Puzzle 2 (HKLM\...\Ravensburger Puzzle 2) (Version: 1.0 - Ravensburger Digital)
Rayman 2 - The Great Escape (HKLM\...\GOGPACKRAYMAN2_is1) (Version: 2.0.0.38 - GOG.com)
Rayman Forever (HKLM\...\GOGPACKRAYMANFOREVER_is1) (Version: 2.0.0.15 - GOG.com)
Rayman Legends Demo (HKLM\...\Steam App 243340) (Version:  - )
Razer Imperator (HKLM\...\{C05905B9-775A-4894-A4DF-B57C15250958}) (Version: 2.02.00 - Razer USA Ltd.)
Razer Synapse (HKLM\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.19.24565 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7399 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver and Utility (HKLM\...\{0DF70CB6-553A-4C57-8E6D-87635EECFB78}) (Version: 1.00.0145 - ALFA NETWORK Inc..)
REAPER (HKLM\...\REAPER) (Version:  - )
Recovery Toolbox for CD Free 2.1 (HKLM\...\Recovery Toolbox for CD Free_is1) (Version:  - Recovery Toolbox, Inc.)
Redneck Rampage Collection (HKLM\...\Redneck Rampage Collection_is1) (Version:  - GOG.com)
Renegade X Black Dawn (HKLM\...\UDK-5848cd63-de6d-4847-9e8d-6abc3bcd6aef) (Version:  - Epic Games, Inc.)
RESIDENT EVIL 5 (HKLM\...\{AC08BBA0-96B9-431A-A7D0-D8598E493775}) (Version: 1.0.0.129 - CAPCOM CO., LTD.)
Resident Evil 6 Benchmark (HKLM\...\{0343CD8E-625A-47FF-BC7E-92BCDF2E5929}) (Version: 1.00.0000 - CAPCOM CO., LTD.)
Resident Evil 6 version 1 (HKLM\...\UmVzaWRlbnQgRXZpbCA2_is1) (Version: 1 - )
Resident Evil Revelations (HKLM\...\Resident Evil Revelations_is1) (Version:  - Capcom)
Resident Evil: Operation Raccoon City (HKLM\...\{43430FA1-12BB-4D88-862E-4F1000008400}) (Version: 1.0.0.0 - CAPCOM U.S.A., INC)
RetroShare (HKLM\...\RetroShare) (Version:  - )
REX 4 - Texture Direct (HKLM\...\{CACCC25C-70B5-4FD1-AF01-10D11B87DED8}) (Version: 4.0.2013.1215 - REX Game Studios, LLC.)
rFactor Demo (HKLM\...\Steam App 353320) (Version:  - Image Space Incorporated)
Rise of the Triad (HKLM\...\GOGPACKROTT2013_is1) (Version: 2.1.0.6 - GOG.com)
RivaTuner Statistics Server 6.2.0 (HKLM\...\RTSS) (Version: 6.2.0 - Unwinder)
RMPrepUSB (HKLM\...\RMPrepUSB) (Version:  - )
RollerCoaster Tycoon 2 Triple Thrill Pack (German) (HKLM\...\GOGPACKRCT2_is1) (Version: 2.0.0.6 - GOG.com)
RollerCoaster Tycoon 3 (HKLM\...\RollerCoaster Tycoon 3_is1) (Version:  - Atari)
RollerCoaster Tycoon Deluxe (German) (HKLM\...\GOGPACKRTC_is1) (Version: 2.1.0.18 - GOG.com)
S.T.A.L.K.E.R. - Call Of Pripyat [v1.6.01] (HKLM\...\{406FB8A4-F539-48A9-809C-F94706F9C9F6}_is1) (Version: 1.6.01 - bitComposer Games)
S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0006] (HKLM\...\S.T.A.L.K.E.R. - Shadow of Chernobyl_is1) (Version: 1.0006 - THQ)
Saints Row The Third (HKLM\...\Saints Row The Third_is1) (Version:  - )
Sang-Froid - Tales of Werewolves Demo (HKLM\...\Steam App 261240) (Version:  - Artifice Studio)
SCANIA Truck Driving Simulator 1.0.0 (HKLM\...\SCANIA Truck Driving Simulator) (Version: 1.0.0 - SCS Software)
Schlag den Raab - Das 3. Spiel (HKLM\...\SDR3) (Version: 1.0 - Sproing Interactive GmbH)
Schlagwortsuche 1.14 (HKLM\...\Schlagwortsuche_is1) (Version:  - Joachim Koopmann Software)
SDFormatter (HKLM\...\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SILENT HILL 4 (HKLM\...\{00BD992A-D4C7-447D-8AA1-60B5759EA30D}) (Version: 1.00.000 - )
SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts)
Singularity(TM) (HKLM\...\InstallShield_{3FAD68D9-1FA1-4871-9ADF-9151D969E943}) (Version: 1.00.0000 - Activision)
SiSoftware Sandra Lite 2014.SP2 (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1) (Version: 20.28.2014.5 - SiSoftware)
SMAC 2.7 (HKLM\...\SMAC 2.7) (Version:  - )
Sniper - Ghost Warrior (HKLM\...\Sniper - Ghost Warrior_is1) (Version:  - )
Sniper Elite V2 (HKLM\...\Steam App 63380) (Version:  - Rebellion)
Sniper: Ghost Warrior - Map Pack (HKLM\...\Sniper - Ghost Warrior - Map Pack/EN-English_is1) (Version:  - City Interactive)
SniperEliteV2 Benchmark 1.05 (HKLM\...\{2BA01EC9-E9F3-453C-AF5B-51E87FD4A0F1}) (Version: 1.05.0000 - Rebellion)
Software Director (HKLM\...\Cloanto Software Director) (Version: 3.8.8.0 - Cloanto Corporation)
Sonic the Hedgehog 4 - Episode II (c) SEGA version 1 (HKLM\...\Sonic the Hedgehog 4 - Episode II (c) SEGA_is1) (Version: 1 - )
SpeedFan (remove only) (HKLM\...\SpeedFan) (Version:  - )
Spintires (HKLM\...\Spintires_is1) (Version:  - )
Splinter Cell: Blacklist (HKLM\...\{28B718F4-73E8-4541-909C-0BA05F7402C2}_is1) (Version: 1.01 - Ubisoft)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Spyware Terminator 2012 (HKLM\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.80 - Crawler.com)
SRWare Iron Version SRWare Iron 41.2200.0 (HKLM\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: SRWare Iron 41.2200.0 - SRWare)
Star Wars: The Old Republic (HKLM\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Starbound with Update 9.5 (HKLM\...\Starbound with Update 9.5) (Version: with Update 9.5 - by Unterbilker)
Starcraft (HKLM\...\Starcraft) (Version:  - )
StarCraft™ II Wings of Liberty (HKLM\...\{7586F650-5D7F-471a-941E-FEF33E580524}_is1) (Version: 1.3.6 - QfG)
StarWind V2V Image Converter V5.6 (build 2011-05-10) (HKLM\...\StarWind Converter_is1) (Version:  - StarWind Software)
StaudSoft's Synthetic World Demo (HKLM\...\Steam App 344920) (Version:  - StaudSoft)
Stone Giant 1.0 (HKLM\...\{1FC46D21-F4A4-42DF-B9A4-27F8A702EBC5}_is1) (Version:  - BitSquid & Fatshark)
Streamripper (Remove only) (HKLM\...\Streamripper) (Version:  - )
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Syndicate (HKLM\...\Syndicate_is1) (Version:  - )
System Shock2 Demo (HKLM\...\SShockDeinstallKey) (Version:  - )
TAP-Windows 9.21.0 (HKLM\...\TAP-Windows) (Version: 9.21.0 - )
Technitium MAC Address Changer v6.0.5 (HKLM\...\TMACv6.0) (Version: 6.0.5 - Technitium)
Teenagent (HKLM\...\GOGPACKTEENAGENT_is1) (Version: 2.0.0.12 - GOG.com)
Telefonbuch für Deutschland (HKLM\...\Telefonbuch für Deutschland) (Version:  - )
Test Drive Unlimited 2 (HKLM\...\Test Drive Unlimited 2_is1) (Version:  - Atari)
Test Drive: Ferrari Racing Legends (HKLM\...\Test Drive: Ferrari Racing Legends_is1) (Version:  - )
The Dude (HKLM\...\Dude) (Version:  - )
The LEGO Movie - Videogame (HKLM\...\The LEGO Movie - Videogame_is1) (Version:  - Warner Bros. Interactive Entertainment)
The Lost Watch II NV 3D Screensaver 1.0 (HKLM\...\The Lost Watch II NV 3D Screensaver_is1) (Version: 1.0 - 3Planesoft)
The Night of the Rabbit Demo (HKLM\...\Steam App 241890) (Version:  - Daedalic Entertainment)
The Witcher 2 - Assassins of Kings Enhanced Edition (HKLM\...\The Witcher 2 - Assassins of Kings Enhanced Edition_is1) (Version:  - GOG.com)
Theme Hospital (HKLM\...\Theme Hospital_is1) (Version:  - GOG.com)
Tom Clancy's Rainbow Six Vegas 2 (HKLM\...\{FD416706-875C-4B0B-A23A-9E740DAE029E}) (Version: 1.00 - Ubisoft)
Tor (remove only) (HKLM\...\Tor) (Version:  - )
Tormentum - Dark Sorrow Demo (HKLM\...\Steam App 347680) (Version:  - OhNoo Studio)
Trend Micro RUBotted 2.0 Beta (HKLM\...\{54D4EAF5-4C80-4878-B4AC-5AE454A02E3C}_is1) (Version: 2.0.0.1034 - Trend Micro, Inc.)
Trials Evolution Gold Edition (HKLM\...\InstallShield_{07D857B8-C956-401D-BC8F-EDA8459AF037}) (Version: 1.0.0.1 - Ubisoft)
Trials Evolution Gold Edition (Version: 1.0.0.1 - Ubisoft) Hidden
Tribler (HKLM\...\Tribler) (Version: 6.4.3 - The Tribler Team)
Ubisoft Game Launcher (HKLM\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Ultra Defragmenter (HKLM\...\UltraDefrag) (Version: 6.0.4 - UltraDefrag Development Team)
Unigine Valley Benchmark version 1.0 (HKLM\...\Unigine Valley Benchmark_is1) (Version: 1.0 - Unigine Corp.)
Universal Adb Driver (HKLM\...\{D9C4202E-6D51-4B06-A8F1-22316E654BCA}) (Version: 1.0.0 - ClockworkMod)
Universal Extractor 1.6.1 (HKLM\...\Universal Extractor_is1) (Version: 1.6.1 - Jared Breland)
Unlocker 1.9.1 (HKLM\...\Unlocker) (Version: 1.9.1 - Cedrick Collomb)
Unreal Gold (HKLM\...\Unreal Gold_is1) (Version:  - GOG.com)
Unreal Tournament  – Game of the Year Edition (HKLM\...\Unreal Tournament  – Game of the Year Edition_is1) (Version:  - GOG.com)
Unreal Tournament 2003 (HKLM\...\UT2003) (Version:  - )
Unreal Tournament 2004 (HKLM\...\Unreal Tournament 2004_is1) (Version:  - GOG.com)
Unreal Tournament 3 Black Edition (HKLM\...\Unreal Tournament 3 Black Edition_is1) (Version:  - )
Uplay (HKLM\...\Uplay) (Version: 4.9 - Ubisoft)
Uplink (HKLM\...\Uplink_is1) (Version:  - GOG.com)
VC 9.0 Runtime (Version: 1.0.0 - Check Point Software Technologies Ltd) Hidden
Virtual CD v10 (HKLM\...\{10C51313-A308-4B40-90E3-B368D5882660}) (Version: 10.10.14 - H+H Software GmbH)
Vistumbler (HKLM\...\Vistumbler) (Version: v10 - Vistumbler.net)
Visual Basic 5.0 (HKLM\...\ST5UNST #1) (Version:  - )
VLC media player (HKLM\...\VLC media player) (Version: 2.2.0 - VideoLAN)
VMware Workstation (HKLM\...\VMware_Workstation) (Version: 10.0.3 - VMware, Inc)
VMware Workstation (Version: 10.0.3 - VMware, Inc.) Hidden
VobSub v2.23 (Remove Only) (HKLM\...\VobSub) (Version:  - )
VPNTunnel 2.0.1.0 (HKLM\...\VPNTunnel) (Version: 2.0.1.0 - )
VTFEdit 1.3.3 (HKLM\...\VTFEdit_is1) (Version:  - Neil Jedrzejewski & Ryan Gregg)
War Thunder Launcher 1.0.1.322 (HKLM\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version:  - 2013 Gaijin Entertainment Corporation)
WaveLab 6 (HKLM\...\WaveLabPro) (Version: 6.1.1.353 - Steinberg)
WebcamMax (HKLM\...\WebcamMax) (Version: 7.8.8.8.MultiLanguage - COOLWAREMAX)
Western Railway NV 3D Screensaver 2.0 (HKLM\...\Western Railway NV 3D Screensaver_is1) (Version: 2.0 - 3Planesoft)
Westwood Chat (HKLM\...\Westwood Chat_is1) (Version:  - )
WhoCrashed 5.03 (HKLM\...\WhoCrashed_is1) (Version:  - Resplendence Software Projects Sp.)
Winamp (HKLM\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows Live ID Sign-in Assistant (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows XP Mode (HKLM\...\{1374CC63-B520-4f3f-98E8-E9020BF01CFF}) (Version: 1.3.7600.16422 - Microsoft Corporation)
Wing Commander III (HKLM\...\{F96B9930-E22A-44D6-81B5-6C8E92C21B4B}) (Version: 2.0.0.2 - Electronic Arts)
Wings 3D 1.5.2 (HKLM\...\Wings 3D 1.5.2) (Version:  - )
WinPcap 4.1.3 (HKLM\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinPlay3 (HKLM\...\WinPlay3) (Version:  - )
WinRAR 5.01 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
WinSCP 5.5.1 (HKLM\...\winscp3_is1) (Version: 5.5.1 - Martin Prikryl)
Wireshark 1.12.3 (32-bit) (HKLM\...\Wireshark) (Version: 1.12.3 - The Wireshark developer community, hxxp://www.wireshark.org)
Wolfenstein 1.11(CREATED BY XEONKING©) (HKLM\...\Wolfenstein 1.11_is1) (Version:  - )
World Racing (HKLM\...\InstallShield_{B151F020-1DEE-4716-944F-2759FC3C51DA}) (Version: 1.01.01 - SYNETIC)
World Racing (Version: 1.01.01 - SYNETIC) Hidden
Worms Armageddon (HKLM\...\Worms Armageddon) (Version:  - )
Worms Reloaded (HKLM\...\Worms Reloaded_is1) (Version:  - )
Wuala (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Wuala) (Version: 1.0.444.0 - LaCie)
x86crt (HKLM\...\{50CBA9D7-4A12-44CA-8E75-9FD7374FBD12}) (Version: 1.0.0 - Microsoft)
XEOX Gamepad SL-6556-BK (HKLM\...\{5E7F3FD4-503B-4451-B2EB-AC8C82DBA32F}) (Version: 1.00.0000 - )
XviD MPEG4 Video Codec (remove only) (HKLM\...\XviD MPEG4 Video Codec) (Version:  - )
yEd Graph Editor 3.13 (HKLM\...\3309-7404-0599-8908) (Version: 3.13 - yWorks GmbH)
You Don't Know Jack 4 1.00 (HKLM\...\You Don't Know Jack 4) (Version: 1.00 - Take 2 Interactive)
Your Freedom 20140128-01 (HKLM\...\Your_Deploy_0) (Version:  - )
Ys Origin English Edition v1.1 - Uninstallation (HKLM\...\Ys Origin English Edition v1.1 - Uninstallation) (Version:  - )
Zak McKracken - Between Time and Space (HKLM\...\Zak McKracken - Between Time and Space) (Version:  - )
Zattoo Live TV (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\6d7aa3e3bf931c56) (Version: 1.0.0.47 - Zattoo Europa AG)
Zip Motion Block Video codec (Remove Only) (HKLM\...\ZMBV) (Version:  - DOSBox Team)
ZoneAlarm Antivirus (Version: 13.2.015.000 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Extreme Security (HKLM\...\ZoneAlarm Extreme Security) (Version: 13.2.015.000 - Check Point)
ZoneAlarm Find My Laptop (Version: 13.2.015.000 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Firewall (Version: 13.2.015.000 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Security (Version: 13.2.015.000 - Check Point Software Technologies Ltd.) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{07474513-7B58-45c7-B3E6-13A3669B1AFD}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{1c492e6a-2803-5ed7-83e1-1b1d4d41eb39}\InprocServer32 -> C:\Program Files\Ubisoft\Trials Evolution Gold Edition\datapack\orbit\npuplaypc.dll (Ubisoft)
CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{2BFFE1F1-509C-5018-A65D-701A661E27A7}\InprocServer32 -> C:\Users\Friedrich\AppData\Roaming\JPLNASAVTAD\NASAEyes\1.0.0.0\npNASAEyes.dll (JPL/NASA-Caltech)
CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{5b55a44a-d008-49aa-9234-86fb7709bc0a}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{97D17A04-4438-4C8E-BAC7-BC21B8B9E999}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)

==================== Restore Points  =========================

18-03-2015 21:09:31 Entfernt Realtek High Definition Audio Driver
18-03-2015 21:14:53 Installiert Realtek High Definition Audio Driver
18-03-2015 21:25:07 Installed Oracle VM VirtualBox 4.3.26
19-03-2015 00:23:03 Entfernt Tt eSPORTS Challenger Ultimate
20-03-2015 18:08:00 Removed Apple Application Support
21-03-2015 18:05:52 Removed Apple Software Update
21-03-2015 19:27:15 Camtasia Studio 8 wird entfernt
22-03-2015 18:37:18 Windows Update
22-03-2015 18:57:47 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-03-19 11:38 - 2015-03-23 05:07 - 00524794 ___RA C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 activate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip4.adobe.com
127.0.0.1 activate.wip4.adobe.com
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {77F35997-F6F3-4A1B-A6EF-DCB05DBF7FCB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-02-19] (Piriform Ltd)
Task: {8DBE0222-73D8-4AC7-BCD5-659CD14297A0} - System32\Tasks\{BF9086B8-0A25-4AB1-8F13-BBB7BC85052F} => pcalua.exe -a C:\Users\Friedrich\Desktop\setup.exe -d C:\Users\Friedrich\Desktop
Task: {F0EBA85F-D539-4520-B198-A26C60FF4DED} - System32\Tasks\{2B4B59FD-A0E1-438D-8B62-9502AF180507} => pcalua.exe -a "E:\Programme\Outlook Express\setup50.exe" -d "E:\Programme\Outlook Express"
Task: {F3596DCE-98A3-45AC-B9EC-3B5823977BDB} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Loaded Modules (whitelisted) ==============

2014-08-25 12:15 - 2014-08-25 12:15 - 00022736 _____ () C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe
2014-06-12 17:22 - 2014-06-12 17:22 - 01261272 _____ () C:\Program Files\VMware\VMware Workstation\libxml2.dll
2014-01-11 03:10 - 2015-02-05 19:27 - 00108864 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-07-04 22:32 - 2010-07-04 22:32 - 00010752 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll
2013-02-04 01:56 - 2008-04-19 16:35 - 00081920 _____ () C:\Program Files\ClamWin\bin\ExpShell.dll
2012-06-18 16:24 - 2012-06-18 16:24 - 00260096 _____ () C:\Program Files\Notepad++\NppShell_05.dll
2014-03-16 05:52 - 2008-08-18 16:08 - 00050688 _____ () C:\Program Files\Virtual CD v10\System\ogg.dll
2014-03-16 05:52 - 2008-08-18 16:11 - 01237504 _____ () C:\Program Files\Virtual CD v10\System\vorbis.dll
2015-02-05 10:20 - 2015-02-05 10:20 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:06A7F9ED
AlternateDataStreams: C:\ProgramData\TEMP:8FCD8443
AlternateDataStreams: C:\ProgramData\TEMP:A5B56640
AlternateDataStreams: C:\ProgramData\TEMP:DA5888A7
AlternateDataStreams: C:\ProgramData\TEMP:FB6A21E3

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-3642466463-2128021046-2334674927-500 - Administrator - Disabled)
Gast (S-1-5-21-3642466463-2128021046-2334674927-501 - Limited - Disabled)
Friedrich (S-1-5-21-3642466463-2128021046-2334674927-1002 - Administrator - Enabled) => C:\Users\Friedrich

==================== Faulty Device Manager Devices =============

Name: Realtek PCIe GBE Family Controller
Description: Realtek PCIe GBE Family Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: RTL8167
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/23/2015 03:38:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: RzSynapse.exe, Version: 1.18.19.24565, Zeitstempel: 0x54f18610
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x531599f6
Ausnahmecode: 0xe0434352
Fehleroffset: 0x0000812f
ID des fehlerhaften Prozesses: 0xdf0
Startzeit der fehlerhaften Anwendung: 0xRzSynapse.exe0
Pfad der fehlerhaften Anwendung: RzSynapse.exe1
Pfad des fehlerhaften Moduls: RzSynapse.exe2
Berichtskennung: RzSynapse.exe3

Error: (03/23/2015 03:38:40 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: RzSynapse.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.IO.FileNotFoundException
Stapel:
  bei Razer.Emily.UI.AppEntryPoint.Main(System.String[])

Error: (03/23/2015 03:38:19 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_seclogon, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003224d
ID des fehlerhaften Prozesses: 0x5b0
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe_seclogon0
Pfad der fehlerhaften Anwendung: svchost.exe_seclogon1
Pfad des fehlerhaften Moduls: svchost.exe_seclogon2
Berichtskennung: svchost.exe_seclogon3

Error: (03/23/2015 03:38:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_NlaSvc, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: nlasvc.dll, Version: 6.1.7601.18685, Zeitstempel: 0x54827c5e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00007cd8
ID des fehlerhaften Prozesses: 0x688
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe_NlaSvc0
Pfad der fehlerhaften Anwendung: svchost.exe_NlaSvc1
Pfad des fehlerhaften Moduls: svchost.exe_NlaSvc2
Berichtskennung: svchost.exe_NlaSvc3

Error: (03/23/2015 03:38:15 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: EMET_Agent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.IO.FileNotFoundException
Stapel:
  bei HelperProcess.Program.Main(System.String[])

Error: (03/23/2015 03:38:08 AM) (Source: WinMgmt) (EventID: 29) (User: )
Description: 0x80041014

Error: (03/23/2015 03:00:09 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: fsbl.exe, Version: 2.2.1092.0, Zeitstempel: 0x48a543e2
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0dce68b8
ID des fehlerhaften Prozesses: 0x5d0
Startzeit der fehlerhaften Anwendung: 0xfsbl.exe0
Pfad der fehlerhaften Anwendung: fsbl.exe1
Pfad des fehlerhaften Moduls: fsbl.exe2
Berichtskennung: fsbl.exe3

Error: (03/23/2015 02:59:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: fsbl.exe, Version: 2.2.1092.0, Zeitstempel: 0x48a543e2
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0dce68b8
ID des fehlerhaften Prozesses: 0xd50
Startzeit der fehlerhaften Anwendung: 0xfsbl.exe0
Pfad der fehlerhaften Anwendung: fsbl.exe1
Pfad des fehlerhaften Moduls: fsbl.exe2
Berichtskennung: fsbl.exe3


System errors:
=============
Error: (03/23/2015 05:28:04 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Trend Micro RUBotted Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (03/23/2015 05:09:11 AM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR6 gefunden.

Error: (03/23/2015 05:09:10 AM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR6 gefunden.

Error: (03/23/2015 05:09:10 AM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR6 gefunden.

Error: (03/23/2015 05:09:09 AM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR6 gefunden.

Error: (03/23/2015 04:16:50 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (03/23/2015 04:16:50 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (03/23/2015 04:16:50 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (03/23/2015 04:16:50 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (03/23/2015 04:16:50 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058


Microsoft Office Sessions:
=========================
Error: (03/23/2015 03:38:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: RzSynapse.exe1.18.19.2456554f18610KERNELBASE.dll6.1.7601.18409531599f6e04343520000812fdf001d06512786e2714C:\Program Files\Razer\Synapse\RzSynapse.exeC:\Windows\system32\KERNELBASE.dllbf9dd1ad-d105-11e4-81fc-005056c00008

Error: (03/23/2015 03:38:40 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: RzSynapse.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.IO.FileNotFoundException
Stapel:
  bei Razer.Emily.UI.AppEntryPoint.Main(System.String[])

Error: (03/23/2015 03:38:19 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe_seclogon6.1.7600.163854a5bc100ntdll.dll6.1.7601.18247521ea91cc00000050003224d5b001d06512501a7710C:\Windows\system32\svchost.exeC:\Windows\SYSTEM32\ntdll.dlla9e0806c-d105-11e4-81fc-005056c00008

Error: (03/23/2015 03:38:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe_NlaSvc6.1.7600.163854a5bc100nlasvc.dll6.1.7601.1868554827c5ec000000500007cd868801d0651251ce12e2C:\Windows\system32\svchost.exec:\windows\system32\nlasvc.dlla8555bff-d105-11e4-81fc-005056c00008

Error: (03/23/2015 03:38:15 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: EMET_Agent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.IO.FileNotFoundException
Stapel:
  bei HelperProcess.Program.Main(System.String[])

Error: (03/23/2015 03:38:08 AM) (Source: WinMgmt) (EventID: 29) (User: )
Description: 0x80041014

Error: (03/23/2015 03:00:09 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: fsbl.exe2.2.1092.048a543e2unknown0.0.0.000000000c00000050dce68b85d001d0650d0d55d59dC:\Users\Friedrich\Desktop\fsbl.exeunknown5503a924-d100-11e4-a045-005056c00008

Error: (03/23/2015 02:59:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: fsbl.exe2.2.1092.048a543e2unknown0.0.0.000000000c00000050dce68b8d5001d0650cf995ead7C:\Users\Friedrich\Desktop\fsbl.exeunknown3b46c82d-d100-11e4-a045-005056c00008


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz
Percentage of memory in use: 38%
Total physical RAM: 3293.82 MB
Available physical RAM: 2041.08 MB
Total Pagefile: 3342.12 MB
Available Pagefile: 2234.07 MB
Total Virtual: 2047.88 MB
Available Virtual: 1891.98 MB

==================== Drives ================================

Drive c: (Lokaler Datenträger) (Fixed) (Total:2048 GB) (Free:81.9 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Medien Datenträger) (Fixed) (Total:1863.01 GB) (Free:332.27 GB) NTFS
Drive f: (Backup Datenträger RED 3TB) (Fixed) (Total:2048 GB) (Free:327.4 GB) NTFS
Drive h: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive i: (64bitGaming) (Fixed) (Total:1862.92 GB) (Free:1537.26 GB) NTFS
Drive x: (RamDisk) (Fixed) (Total:3.89 GB) (Free:3.8 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 379CF46E)
Partition 1: (Active) - (Size=2048 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 02962212)
Partition 1: (Not Active) - (Size=2048 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 0FD998DB)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1862.9 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (Size: 1863 GB) (Disk ID: 03AA03A9)
Partition 1: (Active) - (Size=1863 GB) - (Type=07 NTFS)

========================================================
Disk: 4 (Size: 3.9 GB) (Disk ID: BCB028AD)
Partition 1: (Not Active) - (Size=3.9 GB) - (Type=07 NTFS)

==================== End Of Log ============================


schrauber 23.03.2015 15:51

hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Friedrich_ 23.03.2015 20:57

re3
 
Combofix wie Befohlen ausgeführt. Gab keine Probleme während der Ausführung.
Clickhosterseiten werden weiterhin von svchost besucht. (in abständen von ca 1 minute, mal länger mal kürzer)

Combofix-Log:
Code:

ComboFix 15-03-23.01 - Friedrich 23.03.2015  19:55:21.2.8 - x86
Microsoft Windows 7 Professional  6.1.7601.1.1252.49.1031.18.3294.2308 [GMT 1:00]
ausgeführt von:: c:\users\Friedrich\Desktop\Combo-Fix.exe
FW: ZoneAlarm Extreme Security Firewall *Disabled* {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: ZoneAlarm Extreme Security Anti-Spyware *Disabled/Updated* {98D733EE-E4E4-BC7B-FCCD-3C9EA3D3AC14}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\etc\lmhosts
.
.
(((((((((((((((((((((((  Dateien erstellt von 2015-02-23 bis 2015-03-23  ))))))))))))))))))))))))))))))
.
.
2015-03-23 19:08 . 2015-03-23 19:08        --------        d-----w-        c:\users\hedev\AppData\Local\temp
2015-03-23 19:08 . 2015-03-23 19:08        --------        d-----w-        c:\users\Default\AppData\Local\temp
2015-03-23 08:32 . 2015-03-23 08:33        --------        d-----w-        c:\program files\MiniTool Partition Wizard Free 9.0
2015-03-23 07:20 . 2015-03-23 07:20        --------        d-----w-        c:\programdata\regid.1986-12.com.adobe
2015-03-23 05:22 . 2015-03-23 05:22        238288        ----a-w-        c:\windows\system32\mfevtps.exe
2015-03-23 05:22 . 2015-03-23 05:22        91840        ----a-w-        c:\windows\system32\drivers\mferkdet.sys
2015-03-23 05:22 . 2015-03-23 05:22        648552        ----a-w-        c:\windows\system32\drivers\mfehidk.sys
2015-03-23 02:07 . 2015-03-23 04:29        --------        d-----w-        C:\FRST
2015-03-22 23:40 . 2015-03-22 23:40        --------        d---a-w-        c:\windows\VDLL.DLL
2015-03-22 23:40 . 2015-03-22 23:40        --------        d---a-w-        c:\windows\system32\runouce.exe
2015-03-22 23:40 . 2015-03-22 23:40        --------        d---a-w-        c:\windows\RUNDL132.EXE
2015-03-22 23:40 . 2015-03-22 23:40        --------        d---a-w-        c:\windows\logo_1.exe
2015-03-22 23:29 . 2015-03-22 23:29        34048        ----a-w-        c:\windows\system32\eEmpty.exe
2015-03-22 23:29 . 2015-03-22 23:29        --------        d-----w-        c:\program files\Common Files\MicroWorld
2015-03-22 23:29 . 2015-03-22 23:29        --------        d-----w-        c:\programdata\MicroWorld
2015-03-22 19:37 . 2015-03-22 19:37        --------        d-----w-        c:\programdata\Trend Micro
2015-03-20 22:13 . 2015-03-20 22:13        --------        d-----w-        c:\program files\Trend Micro
2015-03-20 21:57 . 2015-03-20 21:57        --------        d-----w-        c:\program files\Emsisoft HiJackFree
2015-03-20 19:08 . 2015-03-23 03:16        --------        d-----w-        c:\users\Friedrich\AppData\Local\ElevatedDiagnostics
2015-03-20 18:07 . 2015-03-20 18:11        --------        d-----w-        C:\TDSSKiller_Quarantine
2015-03-18 20:39 . 2010-04-07 01:29        81920        ----a-w-        c:\windows\system32\GkSui20.EXE
2015-03-18 20:26 . 2015-03-16 17:44        749664        ----a-w-        c:\windows\system32\drivers\VBoxDrv.sys
2015-03-18 20:25 . 2015-03-16 17:42        104384        ----a-w-        c:\windows\system32\drivers\VBoxUSBMon.sys
2015-03-18 20:25 . 2015-03-18 20:25        --------        d-----w-        c:\program files\Oracle
2015-03-18 20:17 . 2015-03-18 20:17        --------        d-----w-        c:\windows\system32\RTCOM
2015-03-18 20:15 . 2013-10-11 04:47        92584        ----a-w-        c:\windows\system32\CONEQMSAPOGUILibrary.dll
2015-03-18 20:15 . 2012-03-08 03:47        95840        ----a-w-        c:\windows\system32\AERTARen.dll
2015-03-18 20:15 . 2014-06-06 16:00        519368        ----a-w-        c:\windows\system32\AERTACap.dll
2015-03-16 17:42 . 2015-03-16 17:42        115672        ----a-w-        c:\windows\system32\drivers\VBoxNetAdp.sys
2015-03-12 14:27 . 2015-03-23 18:50        --------        d-----w-        c:\users\Friedrich\AppData\Roaming\Everything
2015-03-11 19:41 . 2014-10-14 01:50        2363904        ----a-w-        c:\windows\system32\msi.dll
2015-03-11 19:41 . 2014-08-01 11:35        793600        ----a-w-        c:\windows\system32\TSWorkspace.dll
2015-03-11 19:41 . 2014-10-03 01:45        248832        ----a-w-        c:\windows\system32\WSManMigrationPlugin.dll
2015-03-11 19:41 . 2014-10-03 01:45        214016        ----a-w-        c:\windows\system32\WsmWmiPl.dll
2015-03-11 19:41 . 2014-10-03 01:45        145920        ----a-w-        c:\windows\system32\WsmAuto.dll
2015-03-11 19:41 . 2014-10-03 01:45        1177088        ----a-w-        c:\windows\system32\WsmSvc.dll
2015-03-11 19:41 . 2014-10-03 01:44        198656        ----a-w-        c:\windows\system32\WSManHTTPConfig.exe
2015-03-11 19:01 . 2015-01-17 02:30        828928        ----a-w-        c:\windows\system32\msctf.dll
2015-03-11 19:01 . 2015-02-03 03:12        1230848        ----a-w-        c:\windows\system32\WindowsCodecs.dll
2015-03-11 19:01 . 2015-02-03 03:12        171520        ----a-w-        c:\windows\system32\ubpm.dll
2015-03-11 19:01 . 2015-02-26 03:11        2381312        ----a-w-        c:\windows\system32\win32k.sys
2015-03-11 19:01 . 2015-02-04 02:54        417792        ----a-w-        c:\windows\system32\WMPhoto.dll
2015-03-11 19:01 . 2015-02-20 04:13        26624        ----a-w-        c:\windows\system32\lpk.dll
2015-03-11 19:01 . 2015-02-20 04:13        70656        ----a-w-        c:\windows\system32\fontsub.dll
2015-03-11 19:01 . 2015-02-20 04:13        10240        ----a-w-        c:\windows\system32\dciman32.dll
2015-03-11 19:01 . 2015-02-20 04:13        34304        ----a-w-        c:\windows\system32\atmlib.dll
2015-03-11 19:01 . 2015-02-20 03:09        299008        ----a-w-        c:\windows\system32\atmfd.dll
2015-03-11 19:00 . 2014-12-08 02:46        308224        ----a-w-        c:\windows\system32\scesrv.dll
2015-03-11 16:12 . 2007-08-13 13:51        446464        ----a-w-        c:\windows\system32\wmvdmoe.dll
2015-03-11 16:12 . 2015-03-11 16:27        --------        d-----w-        c:\program files\Active WebCam
2015-03-11 15:57 . 2015-03-11 16:03        --------        d-----w-        c:\users\Friedrich\AppData\Roaming\WebcamZoneTrigger
2015-03-11 11:19 . 2015-03-11 11:19        --------        d-----w-        c:\windows\system32\DCS
2015-03-08 01:02 . 2015-03-08 01:02        --------        d-----w-        c:\program files\LEGO Batman 3 - Beyond Gotham
2015-03-06 04:12 . 2015-03-06 04:12        --------        d-----w-        c:\users\Friedrich\AppData\Local\Apple Computer
2015-03-06 04:11 . 2015-03-06 04:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2015-03-06 04:11 . 2015-03-06 04:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2015-03-06 04:11 . 2015-03-06 04:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2015-03-06 04:11 . 2015-03-06 04:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2015-03-06 04:11 . 2015-03-06 04:11        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2015-03-06 04:10 . 2015-03-06 04:12        --------        d-----w-        c:\programdata\Apple Computer
2015-03-06 03:28 . 2015-03-06 03:28        --------        d-----w-        c:\program files\Common Files\Java
2015-03-05 20:53 . 2015-03-05 20:53        --------        d-----w-        c:\users\Friedrich\AppData\Local\Stardock
2015-03-05 06:50 . 2015-03-05 06:50        --------        d-----w-        c:\users\Friedrich\AppData\Roaming\com.ohnoo.TormentumDemo
2015-03-05 06:31 . 2015-03-05 06:31        --------        d-----w-        c:\users\Friedrich\AppData\Local\SpriteLampWinforms
2015-03-05 05:58 . 2015-03-05 06:03        --------        d-----w-        c:\program files\TClock
2015-03-05 05:04 . 2015-03-05 05:04        --------        d-----w-        C:\Windows Anmeldesounds +Icons AlleSys Bildschirmschoner
2015-03-05 04:49 . 2015-03-05 04:49        --------        d-----w-        c:\programdata\Stardock
2015-03-05 04:48 . 2015-03-05 04:48        --------        dc-h--w-        c:\programdata\{9C3F823B-4738-4CAF-A6B2-69E87FB636C0}
2015-03-05 04:48 . 2015-03-05 04:48        --------        d-----w-        c:\program files\Stardock
2015-03-05 04:47 . 2015-03-05 04:47        --------        d-----w-        c:\users\Friedrich\AppData\Local\PackageAware
2015-03-05 04:28 . 2015-03-05 04:28        --------        d-----w-        c:\program files\MPU
2015-03-05 04:20 . 2015-03-05 04:20        --------        d-----w-        c:\users\Friedrich\AppData\Roaming\Lern-o-Mat
2015-03-05 04:14 . 2015-03-05 04:14        --------        d-----w-        c:\program files\DVDlabPro2
2015-03-05 04:13 . 2015-03-05 04:13        --------        d-----w-        c:\program files\Doc Scrubber
2015-03-05 04:12 . 2015-03-05 04:12        --------        d-----w-        c:\users\Friedrich\AppData\Roaming\jStrip
2015-03-05 04:12 . 2015-03-05 04:12        --------        d-----w-        c:\program files\jStrip
2015-03-05 04:12 . 1999-10-30 01:00        167936        ----a-w-        c:\windows\system32\ccrpftv6.ocx
2015-03-04 05:03 . 2015-03-12 11:34        --------        d-----w-        c:\users\Friedrich\.mediathek3
2015-03-04 05:03 . 2015-03-04 05:03        --------        d-----w-        c:\program files\Mediathekview
2015-03-03 18:32 . 2015-03-03 18:32        --------        d-----w-        c:\program files\K-Lite Codec Pack
2015-03-02 06:04 . 2015-03-23 15:41        --------        d-----w-        c:\program files\Bandicam
2015-03-02 06:04 . 2015-03-02 06:04        --------        d-----w-        c:\program files\BandiMPEG1
2015-02-28 17:06 . 2015-02-05 17:51        621384        ----a-w-        c:\windows\system32\nvStreaming.exe
2015-02-27 15:04 . 2015-02-27 18:00        --------        d-----w-        c:\program files\EMET 5.1
2015-02-26 17:36 . 2015-02-26 17:36        --------        d-----w-        c:\program files\Cain
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-03-23 05:01 . 2014-11-15 19:35        107224        ----a-w-        c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-03-23 05:00 . 2014-03-23 14:42        75480        ----a-w-        c:\windows\system32\drivers\mbamchameleon.sys
2015-03-12 15:44 . 2013-01-29 21:44        778928        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2015-03-12 15:44 . 2013-01-29 21:44        142512        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2015-03-06 03:25 . 2014-01-15 05:51        96680        ----a-w-        c:\windows\system32\WindowsAccessBridge.dll
2015-02-17 14:26 . 2015-02-17 14:26        1217184        ----a-w-        c:\windows\system32\FM20.DLL
2015-02-12 07:55 . 2015-02-12 07:55        9728        ----a-w-        c:\windows\system32\RzStats.IPC.dll
2015-02-05 20:48 . 2014-06-25 13:21        14119744        ----a-w-        c:\windows\system32\nvd3dum.dll
2015-02-05 20:48 . 2014-04-07 23:21        2902784        ----a-w-        c:\windows\system32\nvapi.dll
2015-02-05 20:48 . 2014-01-11 02:10        60560        ----a-w-        c:\windows\system32\OpenCL.dll
2015-02-05 20:48 . 2014-01-11 02:09        908608        ----a-w-        c:\windows\system32\nvhdagenco3220103.dll
2015-02-05 18:27 . 2014-01-11 02:10        4404552        ----a-w-        c:\windows\system32\nvcpl.dll
2015-02-05 18:27 . 2014-01-11 02:10        3058320        ----a-w-        c:\windows\system32\nvsvc.dll
2015-02-05 18:27 . 2014-01-11 02:10        670536        ----a-w-        c:\windows\system32\nvvsvc.exe
2015-02-05 18:27 . 2014-01-11 02:10        2554000        ----a-w-        c:\windows\system32\nvsvcr.dll
2015-02-05 18:27 . 2014-01-11 02:10        61768        ----a-w-        c:\windows\system32\nvshext.dll
2015-02-05 18:27 . 2014-01-11 02:10        375112        ----a-w-        c:\windows\system32\nvmctray.dll
2015-02-05 00:24 . 2014-12-14 02:10        20416        ----a-w-        c:\windows\system32\drivers\rzpmgrk.sys
2015-02-04 00:30 . 2015-02-04 00:30        225        ----a-w-        c:\users\Friedrich\IP_Log_Data.js
2015-01-14 10:27 . 2014-09-12 19:21        2894848        ----a-w-        c:\windows\system32\pwNative.exe
2014-12-30 09:35 . 2014-12-30 09:35        151336        ----a-w-        c:\windows\system32\drivers\rzudd.sys
2014-12-30 09:28 . 2014-12-30 09:28        990720        ----a-w-        c:\windows\system32\rzdevicedll.dll
2014-12-30 09:28 . 2014-12-30 09:28        78848        ----a-w-        c:\windows\system32\rzvirtualdev.dll
2014-12-30 09:28 . 2014-12-30 09:28        155136        ----a-w-        c:\windows\system32\rztouchdll.dll
2014-12-30 09:28 . 2014-12-30 09:28        117248        ----a-w-        c:\windows\system32\rzdisplaydll.dll
2014-12-30 09:28 . 2014-12-30 09:28        419840        ----a-w-        c:\windows\system32\rzaudiodll.dll
2013-07-08 16:34 . 2013-10-28 20:15        2699264        ----a-w-        c:\program files\wPrime.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DMS-Kalenderchen"="c:\program files\Kalenderchen\Kalenderchen.exe" [2010-05-18 3498496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VC10Player"="c:\program files\Virtual CD v10\System\VC10Play.exe" [2011-10-19 411976]
"USB3MON"="c:\program files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-02-22 292088]
"ISW"="c:\program files\CheckPoint\AKL\AkSA.exe" [2014-05-14 638584]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-12-13 135536]
"Razer Synapse"="c:\program files\Razer\Synapse\RzSynapse.exe" [2015-02-28 590144]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
.
c:\users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
allSnap.lnk - c:\program files\allSnap\allSnap.exe [2013-1-30 90112]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute        REG_MULTI_SZ          autocheck autochk *\0OODBS
.
R1 Uim_Vim;UIM Virtual Image Plugin;c:\windows\system32\Drivers\Uim_Vim.sys [2012-11-22 283600]
R2 nlndis;NetLimiter 3 NDIS driver;c:\program files\NetLimiter Ndis Miniport Service\nlndis.exe [2011-10-05 32768]
R2 VMwareHostd;VMware Workstation Server;c:\program files\VMware\VMware Workstation\vmware-hostd.exe [2014-06-12 14407384]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files\Futuremark\SystemInfo\FMSISvc.exe [2015-02-09 614624]
R3 GKBFltr;Gaming Keyboard;c:\windows\system32\Drivers\GameKB.sys [2009-12-29 19328]
R3 HH10Help.sys;HH10Help.sys;c:\windows\system32\drivers\HH10Help.sys [2010-03-10 13952]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
R3 icsak;icsak;c:\program files\CheckPoint\AKL\ak\icsak.sys [2014-05-14 39296]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-02-20 102912]
R3 IswSvc;ZoneAlarm AntiKeylogger IswSvc;c:\program files\CheckPoint\AKL\AkSVC.exe [2014-05-14 749176]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2015-03-23 91840]
R3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys [2011-03-21 5230088]
R3 Origin Client Service;Origin Client Service;c:\program files\Origin\OriginClientService.exe [2015-03-04 1910640]
R3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-11-24 13440]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2013-09-30 15688]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2013-09-30 10320]
R3 Realtek87B;Realtek87B;c:\program files\Realtek\RTL8187 Wireless LAN Utility\RtlService.exe [2009-12-07 40960]
R3 RTCore32;RTCore32;c:\program files\MSI Afterburner\RTCore32.sys [2013-03-11 5632]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2013-04-10 651848]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187.sys [2010-01-07 375808]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 t_mouse.sys;HID-compliand device;c:\windows\system32\DRIVERS\t_mouse.sys [2012-12-19 5120]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R4 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;c:\program files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
R4 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;c:\program files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
R4 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;c:\program files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
R4 EMET_Service;Microsoft EMET Service;c:\program files\EMET 5.1\EMET_Service.exe [2014-11-09 31880]
R4 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys [x]
R4 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [x]
R4 Razer Game Scanner Service;Razer Game Scanner;c:\program files\Razer\Razer Services\GSS\GameScannerService.exe [2015-02-05 187072]
R4 RUBotSrv;Trend Micro RUBotted Service;c:\program files\Trend Micro\RUBotted\RUBotSrv.exe [2013-07-25 443416]
R4 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\Spyware Terminator\st_rsser.exe [2013-01-14 587912]
S0 iaStorA;iaStorA;c:\windows\system32\drivers\iaStorA.sys [2012-09-01 532536]
S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys [2012-09-01 25656]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\drivers\iusb3hcs.sys [2013-02-22 16880]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2013-01-30 436792]
S0 SscRdBus;RamDisk bus enumerator;c:\windows\system32\DRIVERS\SscRdBus.sys [2014-11-22 88296]
S0 SscRdCls;RAM Disk (SuperSpeed LLC);c:\windows\system32\DRIVERS\SscRdCls.sys [2007-12-19 40984]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2013-10-08 71888]
S0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys [2013-10-08 63824]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2014-04-30 25696]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys [2014-04-30 43608]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys [2014-04-30 144352]
S1 nltdi;nltdi;c:\program files\NetLimiter 3\nltdi.sys [2011-03-21 5281672]
S1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2011-06-21 32768]
S1 Uim_DEVIM;UIM Direct Device Image Plugin;c:\windows\system32\DRIVERS\uim_devim.sys [2013-12-26 20616]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2015-03-16 749664]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2015-03-16 104384]
S1 vdrv1000;vdrv1000;c:\windows\system32\DRIVERS\vdrv1000.sys [2011-04-19 186392]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2013/03/04 20:14];c:\program files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 09:16 77296]
S2 Dokan;Dokan;c:\windows\system32\drivers\dokan.sys [2014-08-25 105680]
S2 DokanMounter;DokanMounter;c:\program files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe [2014-08-25 22736]
S2 ISWKL;ZoneAlarm AntiKeylogger ISWKL;c:\program files\CheckPoint\AKL\ISWKL.sys [2014-05-14 42880]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2015-03-23 238288]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2013-03-01 36600]
S2 ntk_PowerDVD;ntk_PowerDVD;c:\program files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [2011-04-20 71664]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2013-01-07 2505160]
S2 ParagonLDM;ParagonLDM;c:\windows\system32\drivers\biont_bs.sys [2014-04-11 24512]
S2 rzpmgrk;rzpmgrk;c:\windows\system32\drivers\rzpmgrk.sys [2015-02-05 20416]
S2 rzpnk;rzpnk;c:\windows\system32\drivers\rzpnk.sys [2014-11-17 97088]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-02-05 410952]
S2 VC10SecS;Virtual CD v10 Management Service;c:\program files\Virtual CD v10\System\VC10SecS.exe [2011-10-19 144712]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2014-02-27 722624]
S2 vstor2-mntapi20-shared;Vstor2 MntApi 2.0 Driver (shared);c:\windows\system32\drivers\vstor2-mntapi20-shared.sys [2013-02-22 23632]
S2 WCMVCAM;WebcamMax, WDM Video Capture;c:\windows\system32\DRIVERS\wcmvcam.sys [2012-04-15 1068216]
S2 ZAPrivacyService;ZoneAlarm Privacy Service;c:\program files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [2014-05-29 90936]
S2 ZoneAlarm AntiTheft;ZoneAlarm AntiTheft;c:\program files\CheckPoint\AntiTheft\Antitheft.exe [2014-05-30 3128968]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys [2013-02-22 352752]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys [2013-02-22 796656]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt32.sys [2009-11-17 24664]
S3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECI.sys [2012-07-02 55104]
S3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys [2011-03-21 5230088]
S3 rzendpt;rzendpt;c:\windows\system32\DRIVERS\rzendpt.sys [2014-12-17 35624]
S3 rzudd;Razer Mouse Driver;c:\windows\system32\DRIVERS\rzudd.sys [2014-12-30 151336]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2015-03-16 115672]
.
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about:Tabs
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
IE: Mit GetRight downloaden - c:\program files\GetRight\GRdownload.htm
IE: Mit Getright-Browser öffnen - c:\program files\GetRight\GRbrowse.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
LSP: %windir%\system32\vsocklib.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: Interfaces\{540DE981-1465-410D-993D-5B1652998DCB}: NameServer = 192.168.44.44
FF - ProfilePath - c:\users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: keyword.enabled - false
FF - prefs.js: network.proxy.ftp - 127.0.0.1
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - 127.0.0.1
FF - prefs.js: network.proxy.gopher_port - 4001
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
ShellIconOverlayIdentifiers-{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
ShellIconOverlayIdentifiers-{BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
HKCU-Run-AdobeBridge - (no file)
AddRemove-KKND Krossfire - c:\windows\IsUn0407.exe
AddRemove-Worms Armageddon - c:\windows\IsUn0407.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vdrv1000]
"ImagePath"="system32\DRIVERS\vdrv1000.sys"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3642466463-2128021046-2334674927-1002\Software\SecuROM\License information*]
"datasecu"=hex:c7,15,75,53,3d,b3,5d,7f,9b,c6,f5,f3,2f,c2,16,a3,da,53,25,de,e3,
  99,91,51,ff,53,aa,05,db,39,b7,46,71,16,a9,07,e4,85,4f,1c,70,3b,b7,71,2f,ed,\
"rkeysecu"=hex:57,0c,82,4e,90,49,51,8c,16,37,44,be,9c,90,bb,17
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_17_0_0_134_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_17_0_0_134_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="25B6FBFD8570F38A4FDD7964F47D6A3BCED895794865D15C39AFE4FBD07F3CFE14A09F4B53DC58661DE0FB61102A5370961C1022DEE24545AD50CEF4564AB0DF6C7707B48BC492DEBBFC0167D8F2FB2DF58B9CCFB724C5F3881E12462D934D5FA6EF2F68C7FE42328F2FB4119F0205AD5A883829FDC817C05DFE1C43FA1095132016970644F44DD35CC4C9EBDC95556090C6E44980853D39232C603406874F4797C7C2A461A1DA6C4AE4F3F92900946CC950A84032208420B5B35655BAD507F832B739CCA59857D6E884EBB042A630A81F810D8F2AF4FA695576F6D5296C0B5BF86E067A397EF2A1296FEC7B8A85D8230A0B1F30FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA9C6AECB7A5D1407FEBC9E127BECC74C8EDD5E5BE2F6E667A6171C11EC38DE3D82685B72FADFCBC06DDD0F896D8D2E61006487386AF94E34CC9115591A00930D3C0E25EE7E03258D94EFAA86C470D1F61BEC8570289F844035DD07C0E3F34D872C097926B559734C7148450BF28B22FBF8789A10A3AF1AD0AB37354BC039F67BD575A15FEB278D9E3B59A85C470848A0AE6B32F9D6D7A542B91A491973233A0FDC07AA164C82C999D2A9E1F1F9E2EA8471C27843219AC0629117B37B255940620901E27BE8D9054937544279A56BB8C19C8D6035C6CD0C7705D1267862563B04C9BC6071B8EA21A990065ED3C747E3E1AD6E204DED992AB98E82994B9AE7DCFA2E28F910924A012EA7818F93C2EF22654A9DB2BCA2FDBF52C7F5C8E223B2DC3E6CC44C23365F8FBDEA1D7303DEB12CBDB7E4556AD44B7964F10DB16134AB783DDB2738A9C365382F6CC36A1FC42C40D1E1A58AEED6A785826FBA971EE91EED577AF86057406EEA5361731A958256A07D56519718600D9535C9880421C42981616AF72E1496DB1EEAA43E6CCD8B771190486E08668DC860782C923FAB293F79246DF4CCF91366482DB2C90D5FB6AC5D4C0F9BA911DDFCA13BE68759AFE028A4DEED552D5B671AE743AE526D17BCE6D16826850E01B31F18626EAC265395FCCF40799182B8A8567DCADD2444F4BDE9C011AAEF0BD3577905C6D85BBBF05A2D4F6E41B746CBD04E8CD52A22082DBAD0FEE3E032BCD9F22A3033E27EF596A17CFA8218E8B3FEBC8A1EEBA2C1F8A89A0666F3AF387E99972264E86C17740745002E8979DA4B722EE64085778F1605284B56492280F44C37A76E1A7AB899B901A4498301D6D1784A138090FEA7A41111B5AEDDE51E05602AD324EF330C0D59F3A630E66EB8CD1A9A1377F0B4BD2E5369AD55214FB9D8772C945987E2CDB8C2251B499BA8730D928DBE3A7AB3170181A56FB3F6D40DDEE45BAC6A6E7BCD4D0A7B6781FEB78B9E5172C0E778C08EAC8A208D38351168C9343C31B4AA8E70BDF4"
"OODEFRAG15.00.00.01PROFESSIONAL"="C7B67DAA3183EB11CDFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA9C6AECB7A5D1407BA7FD869164D67949DB7CE019D40AA5C9DB7CE019D40AA5CDB37C3DAD8801333340B3D7D88419060679E51434A6B4530B9D835E36DAE465EF06D40058639422FD35E6C2D19BDEF23788A2E458F0943C8E74D1B2C05A504110E2AD657DC981FBAF68D600A2AA25FD1621A1F8FE998DEB32689CD968BC9D82C5817A88DC8F5C623580278974D574AD015196090B0B2EC8DB75A879ABD0228A90CA30CC60C2CC658C76C46C069470D2A16975F1A8EF2381AF7D134932B3D4AA2F8818905BD18A46DAC3E12503962F88AFEE9416084FB7F3D56C5F33EB9EC885602A65EB1459E591A7DB0D377CC9C52427D285E7E66717303534D9C3D2207A3A71ECCFB17E2244EBB453EBC49856CD2C651AEBFEFDBFABA988747B59871844D9DD77489662795E5D026252DBF9ACF2631529E279760466FCE9AD4FBB907E32CE2CFDB5FB0775FF2FDD369BC3696C36F3DE6D987B943059F9CCBD960ED9926DBC6B88D0CED0FF53E0B9651366E594DC24D0E89070129E84C9A6E008569B0516CBB5A504F7979CF8362C969178A947429E5D79B037A0A2E6C8968B44741296F5FD910339F941B66F117DF7F9394CEC39E2FEBBC0A96310FEA4832A92FF0340D2DD9470926DFA7B92E5ADAA710F863CB96F50164E0ABBE4C24DD5C527FD5D5BBBE9B86E7C1E32A4B5105D3B7A807019F73AC66497DF225AB6B7408E9AB33E81375A3E129828D7FA2E513F7CCABF42B579066FB668B89AE7505D96CEBDDAE172AA39686EB2EAADA49ECA306459AD8B70FB8DD36FDEAF074F52D7FD11BF053E3218EC03311BEEDBF4FD8FCD3C32D31D0E42EED2193AF0FE7FC117C187B758EA217F3113A40E0708A47930448AF4EDD77FDA59958EE21ACCB62D109B256B0357C3480980462F72DE64679C660341AA27C01C8058C9BB9F7397B8605A5B79B7AEDA059100DA69703D7E7D7F22CC0E52707993578046B2B019AA5B9700BF2617AC80A945262FE8AB4B24BF45FD08836F992F879E018F1D63FB0C2E672939CE23430A33CDD27A04D6BA01309018482C70A6CD09CCFB48555098EB503D4FE0D36089E205155150792B221E53E76956885ACB8D917785DC4721F1DE9F20526E122BE5EBB440075EE3F77046C36FD64BB961AEE4F56B7A58EAC2017C81014F0FCA38093B3FE48A8DB6C0F705884FBE3BE4DED5871B986370738140C4429B9DD02EBDDB0495ABD2192E730DF5AB1F79B7837A813839907CF97FC62615200CE01DA5E4800C0A692661F34761F29B81EAA34112F14CC3BFDC0EA95594DE94BD17F3414959CE6269E924D8562D1000A3EBE00CD4AA0995ED4EE72D129DB88B36493015901778610DCD7314555EB9E09"
"OOSAFEERASE04.00.00.01MSWINDOWS"="B69E66F040165E9246AA6B4660FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA9C6AECB7A5D1407BA7FD869164D67949DB7CE019D40AA5C5D575E7D6A3B9808D748C5EDAF1BF2D57E92655A2BFDEC17789422B74739FD39AED5896BB2B3A3B6D0679E4A4B8C412BC0876D5B8383E18C5DD1789185F8457D9404702CB47344274B4DB915F73D7FAC8BB5495D580DE1268D894A416B426BB00CE29540122DD88EE7B9FC3F016B11501D046444A1D0E39904EA25BABEE59DEA6D0CCCCA7AEA64847C4D213DA37AECCFE6BE7AF54CACF4E1EF8AEC76B6599C88C1FC3FF516DB7C689010B20C15F01DAB0F949FDD371F37403361D86E03B53F2A4B15E66E7DD04BD960EA13A5FA79C2A26E99B7E9B64CDBB6E44B72A2C1B6ECB2FB9C16633F40103EDD2C758EF0E3103E93C47C0D147C2C0CCE0A18190ABE24C9FC3BED8A5DC39CBF2C87E3CA06224DC6BD727DBE881B854C6F407ED5E45175DE28FD671CCE99564AA3133BE3BCCB554AE4609B78C738D6467976AA66CE99071E0D574E55FB23380FD2C82C688D9C161B32B28B397208258B541B795B386111FEF01DC2F643E6D005F6863B6AE0F095D08171588323E188F5197B9747861BE237C88737C4F60E42E10810C0FD984DE843E5075FDE64C1AD1F17CE88C113DCDAC343B47407DDE643A62C8AE9BD8659BB9225C3D2543648D4E651AB22E52B5E6FE4BCA5168CB0649D12410138C6705FCD1FB6DA37F38D39516F7D8F91540F7B2B9FCAC08C239D1AAEA9D6E17FBB13CC71904A6267CFD17B0DA006DA53317437AABA344D1B2248C4E9B6327F69411EB60F5041D712FE5F9C022589513BA203351E42747AD9DF453FD547CB11F002B153A20D2F99371C064AC1EC5B1A7055DABD4B88BBD933BB1E0E0C2BCF2FE92B67FC39B8DF6BAC450ADA712A82C4EC78893F8C9FEC5FE793D2553A781ED9F5EDC8B1F6094FF39D9DA2C448D4B6BFFE40164A4D5F9FE50C4DD3DFA4874DF18F7FD6171478B0BE864B7D239228695F4B63781311659F2907D1071C1FF524BF831C82F1DA45E6BB3A793938B0A2BBDCC69E1FF2EA116CCC158D489A16A49FEB71FDB3AEAB710F3EDE57E9E5170804553DB1E9E6068739D345F0631186B9F006CF6944DA78C2F2FCEB169735CE5E4E464DDE2E109E2FEDA97BF09B5B839D7B80E52385294944179531EC3FD1F172D79668EE34B20635269AEF8526F532FCD73151F339713843AE04CF17CF0B33D1938ED72DBA37A28AB0D82EAC2E03CD4954D2822B952FF6D2A4AD3ED2AE5555D027D8346971AB6B6111F89666D0C924396F03BD99C77FC6C817DA45E2B2C831066E07ED767DC16F3400F45BB6213198C25E459D94EC267F3ED5B4038D28A033CDF78E46AD78CB4FBD68A98626234920A609FE0D"
"OOSE05.00.00.01PRO"="A661E26EF493636F9AA5990DD794AB4924380A2B8563524362ECA0B895919B328B22C5FD1E87CB2F8AE45FA0327ED5226EAD9FAC3FFA4CDD202DA7B52BE630BC76A3F30848AA855E0C4B2260A06BBD6CF2D5FD3F8140EEEEA973E248E612DCB56CEF6CACAEF2544DD1DCF52E1897CC85B2CAEDA71ED868886C9371B41CC0B600EA3742D3BCB551CE044384B2C3A54252A3CF4CEF9FCCBC3E4C098683CE852681604B9EA796AEEB383EC788570218B1B92E480C613E0AC52A1EF166823758FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA9C6AECB7A5D14079DB7CE019D40AA5CBA7FD869164D6794A6A0AC4980AC793381594EF6A22DB11FEB5FE823B521F0156622E1820C429B0307C38B702663B757A208EA01DF13AE1A3FE6EE529335F38860B3855F0B357B339CD771EF3CC1F9300794F813DE9BFEDD695B622548775336C9B2BF6E9D653233C5B08DCB56D84ABCB9FD1CEA89AC172EB86CCF92114CFE6A551FA87E78584D78BCC0A44ABCED73BC994767695E6D1E37D15039B4C25D1C580E7F5183E25910DF0F7D75D64A8E73D45979E4926D4970052CBD9448C2180415CEDD3B143775EDA71D632F82F1087D8EFE9E91105BF11E099473CC300AAD419CC7C65EE966FE91F49E70F400356E7654E5475E2FE3D9E7192A30BFF1A792954D804B26E4F18BD84D1C27E0282E187AF7BC07305FD1BA486DE03A3FB8BE017568CF8370887277D41EF48E7D7788A2D8AC077560360710E8257F5990CF05758995628711F992DD4A3459314B0C0469118C1BAE3BEDF91AAA40A25A6E2A43B02D5FB9F44F06122434C5CF1C3DAA76125C1223D18262B2DB1FA43A8E085FD939F132AA6E651BC3ECBE68B165BDBB4604241F1E816B13CE1F8F9B0AC8FD273BD61DE15C19024A8EA54C18ACA0264AF06808F760671EA7FEEFF7D3A8E3E5E06C9626A44E9D4ACC6E7A7234C2E9480786B059440EAEB7670A1D855C84BA4A0D86CA39164F2A537C725D79FE4A5F66C4AB0F9E112386CA3F483C1E2D5A2F29533B88373205F028D83E0661A1EB24BBFC17F9934E6FA15A4027A4D89CBFA5757BC9A7B55DE728C70408EDD82727DD70CA96AC2450143A601F27F27F6B1C8615F50BC67BDCC48727459CD2477FCBB8A7ED0B27F5CF098949B55F871338AABD60D2E6C606DBBCCE2B87D93745FB01617349E62D5E6998CF777F7785488A7C3EA6C85BCB8668C3BDB059B3E1A055BF8C5DE632C3E71D6152BE1E2D5683CAF3792AB0FDBE5FF3239B046EB1DADBA6D57060718BB7505057D569D652A46245C96BA00A72CEACD677B1EB9D6FF22B7066C66C39A1988A49BE29B113CA62342D898E34F473EBB6CA324D9BE01A3AF894654E65B1B8B63E36B498CB5D12C1FC9712E302B84F4B016D97BE"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2015-03-23  20:12:05
ComboFix-quarantined-files.txt  2015-03-23 19:12
.
Vor Suchlauf: 33 Verzeichnis(se), 87.921.111.040 Bytes frei
Nach Suchlauf: 34 Verzeichnis(se), 87.566.884.864 Bytes frei
.
- - End Of File - - 3CCC0EA501EA2F616C499AF40A4FF115
A36C5E4F47E84449FF07ED3517B43A31


schrauber 24.03.2015 10:34

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.

Friedrich_ 25.03.2015 09:21

re4
 
Malwarebytes-LOG
Code:

Malwarebytes Anti-Malware
www.malwarebytes.org


Update, 25.03.2015 06:56:02, SYSTEM, DSLSERVICE, Manual, Malware Database, 2015.3.25.1, 2015.3.25.2,
Update, 25.03.2015 06:56:11, SYSTEM, DSLSERVICE, Manual, Failed, Unable to access update server,
Scan, 25.03.2015 07:25:35, SYSTEM, DSLSERVICE, Manual, Start: % 1 "% 2", Dauer: % 1 min 29 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, 0-Malwareerkennung,

(end)

ADWCleaner-LOG
nicht gelöschte Beiträge sind FALSE-POSITIVES! und gehören zu meinem Programm und einstellungsrepertoire
Code:

# AdwCleaner v4.113 - Bericht erstellt 25/03/2015 um 07:37:05
# Aktualisiert 22/03/2015 von Xplode
# Datenbank : 2015-03-23.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x86)
# Benutzername : Friedrich - DSLSERVICE
# Gestarted von : C:\Users\Friedrich\Desktop\Sicherheitsprogramme\AdwCleaner_4.113.exe
# Option : Löschen

***** [ Dienste ] *****

[x] Nicht Gelöscht : sp_rsdrv2

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\Windows\Uninstaller
Ordner Gelöscht : C:\Users\Friedrich\AppData\Local\PackageAware
[x] Nicht Gelöscht : C:\Windows\system32\drivers\sp_rsdrv2.sys

***** [ Geplante Tasks ] *****


***** [ Verknüpfungen ] *****

[x] Nicht Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paragon Hard Disk Manager™ 14 Suite\Uninstall Paragon Hard Disk Manager™.lnk
[x] Nicht Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NovaLogic\Delta Force 2\Uninstall.lnk
[x] Nicht Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NovaLogic\Delta Force\Uninstall.lnk

***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi
Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A1CCCE0D-AE21-42A2-BE58-8E6109410995}
Schlüssel Gelöscht : HKCU\Software\Headlight
Schlüssel Gelöscht : HKLM\SOFTWARE\Headlight
[x] Nicht Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\allSnap_is1
[x] Nicht Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sonic the Hedgehog 4 - Episode II (c) SEGA_is1
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>

***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17689


-\\ Mozilla Firefox v36.0.4 (x86 de)


-\\ Chromium v


*************************

AdwCleaner[R0].txt - [2696 Bytes] - [05/07/2014 01:32:15]
AdwCleaner[R10].txt - [2972 Bytes] - [19/03/2015 05:08:27]
AdwCleaner[R11].txt - [3033 Bytes] - [19/03/2015 08:52:58]
AdwCleaner[R12].txt - [2906 Bytes] - [22/03/2015 22:42:07]
AdwCleaner[R13].txt - [2748 Bytes] - [23/03/2015 03:01:35]
AdwCleaner[R14].txt - [2898 Bytes] - [25/03/2015 07:30:51]
AdwCleaner[R1].txt - [2108 Bytes] - [05/07/2014 01:44:43]
AdwCleaner[R2].txt - [2092 Bytes] - [05/07/2014 01:51:47]
AdwCleaner[R3].txt - [2152 Bytes] - [22/07/2014 16:45:56]
AdwCleaner[R4].txt - [2309 Bytes] - [27/08/2014 00:30:24]
AdwCleaner[R5].txt - [2646 Bytes] - [27/08/2014 15:45:37]
AdwCleaner[R6].txt - [2706 Bytes] - [27/08/2014 15:51:46]
AdwCleaner[R7].txt - [2858 Bytes] - [01/09/2014 18:35:30]
AdwCleaner[R8].txt - [2695 Bytes] - [20/12/2014 19:07:20]
AdwCleaner[R9].txt - [2912 Bytes] - [10/03/2015 19:00:19]
AdwCleaner[S0].txt - [2649 Bytes] - [05/07/2014 01:39:52]
AdwCleaner[S1].txt - [2061 Bytes] - [05/07/2014 01:48:59]
AdwCleaner[S2].txt - [2843 Bytes] - [19/03/2015 09:34:59]
AdwCleaner[S3].txt - [2996 Bytes] - [25/03/2015 07:37:05]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [3055  Bytes] ##########

Junkware Removal Tool-LOG
Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.5 (03.17.2015:1)
OS: Windows 7 Professional x86
Ran by Friedrich on 25.03.2015 at  7:50:49,49
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.03.2015 at  7:53:27,97
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

FRST-LOG

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by Friedrich (administrator) on DSLSERVICE on 25-03-2015 07:57:30
Running from C:\Users\Friedrich\Desktop\Sicherheitsprogramme
Loaded Profiles: Friedrich (Available profiles: Friedrich)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
(H+H Software GmbH) C:\Program Files\Virtual CD v10\System\VC10SecS.exe
(VMware, Inc.) C:\Windows\System32\vmnat.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(H+H Software GmbH) C:\Program Files\Virtual CD v10\System\VC10Play.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Check Point Software Technologies LTD) C:\Program Files\CheckPoint\AKL\AkSA.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\AntiTheft\Antitheft.exe
(VMware, Inc.) C:\Windows\System32\vmnetdhcp.exe
(VMware, Inc.) C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
(NirSoft) C:\Program Files\TcpLogView v1.12\TcpLogView.exe
(NirSoft) C:\Program Files\HTTPNetworkSniffer v1.35\HTTPNetworkSniffer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [VC10Player] => C:\Program Files\Virtual CD v10\System\VC10Play.exe [411976 2011-10-19] (H+H Software GmbH)
HKLM\...\Run: [USB3MON] => C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM\...\Run: [ISW] => C:\Program Files\CheckPoint\AKL\AkSA.exe [638584 2014-05-14] (Check Point Software Technologies LTD)
HKLM\...\Run: [LifeCam] => C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\Run: [Razer Synapse] => C:\Program Files\Razer\Synapse\RzSynapse.exe [590144 2015-02-28] (Razer Inc.)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [153672 2010-06-14] (Logitech Inc.)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Run: [DMS-Kalenderchen] => C:\Program Files\Kalenderchen\Kalenderchen.exe [3498496 2010-05-18] (Daniel Manger Software)
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\allSnap.lnk
ShortcutTarget: allSnap.lnk -> C:\Program Files\allSnap\allSnap.exe (Ivan Heckman)
SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll (Stardock.net, Inc)
BootExecute: autocheck autochk * OODBS

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-06] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-06] (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{540DE981-1465-410D-993D-5B1652998DCB}: [NameServer] 192.168.44.44

FireFox:
========
FF ProfilePath: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default
FF NewTab:
FF Homepage: about:blank
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.http", "");
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.http_port", 0);
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.no_proxies_on", "");
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.share_proxy_settings", true);
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF NetworkProxy: "backup.ftp", "127.0.0.1"
FF NetworkProxy: "backup.ftp_port", 8080
FF NetworkProxy: "backup.gopher", "www-proxy.t-online.de"
FF NetworkProxy: "backup.gopher_port", 80
FF NetworkProxy: "backup.socks", "127.0.0.1"
FF NetworkProxy: "backup.socks_port", 8080
FF NetworkProxy: "backup.ssl", "127.0.0.1"
FF NetworkProxy: "backup.ssl_port", 8080
FF NetworkProxy: "ftp", "127.0.0.1"
FF NetworkProxy: "ftp_port", 8080
FF NetworkProxy: "gopher", "127.0.0.1"
FF NetworkProxy: "gopher_port", 4001
FF NetworkProxy: "http", "127.0.0.1"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "no_proxies_on", ""
FF NetworkProxy: "pong", ""
FF NetworkProxy: "pong_port", 0
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "127.0.0.1"
FF NetworkProxy: "socks_port", 8080
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "127.0.0.1"
FF NetworkProxy: "ssl_port", 8080
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-12] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll [2013-12-05] (Adobe Systems, Inc.)
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\PDF-XChange Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @esn/npbattlelog,version=2.4.0 -> C:\Program Files\Battlelog Web Plugins\2.4.0\npbattlelog.dll [2014-05-26] (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-06] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-06] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @nullsoft.com/winampDetector;version=1 -> C:\Program Files\Winamp Detect\npwachk.dll [2013-12-13] (Nullsoft, Inc.)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\PDF-XChange Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin HKU\S-1-5-21-3642466463-2128021046-2334674927-1002: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\PDF-XChange Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-3642466463-2128021046-2334674927-1002: eyes.nasa.gov/NASAEyes -> C:\Users\Friedrich\AppData\Roaming\JPLNASAVTAD\NASAEyes\1.0.0.0\npNASAEyes.dll [2013-08-02] (JPL/NASA-Caltech)
FF Plugin HKU\S-1-5-21-3642466463-2128021046-2334674927-1002: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Trials Evolution Gold Edition\datapack\orbit\npuplaypc.dll [2013-03-18] (Ubisoft)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-03-06] (Apple Inc.)
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\a9.xml [2013-06-01]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\blekko-https.xml [2015-03-18]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\blekko.xml [2015-03-18]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\duckduckgo.xml [2012-07-03]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\expediadotcom.xml [2007-03-08]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\flickr-tags.xml [2013-07-08]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\geizhalseu.xml [2015-03-02]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\geo-ip-tool.xml [2014-10-04]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\gutscheinrauschde-suche.xml [2011-03-22]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\hollywoodcom.xml [2013-10-05]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\imdb.xml [2008-10-22]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\ixquick-ssl.xml [2014-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\lycos-europe.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\MSN.xml [2013-10-05]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\neckermannde.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\otto.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\qwantcom.xml [2014-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\spinde.xml [2009-03-16]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\t-online.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\weathercom.xml [2015-03-18]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\wolframalpha.xml [2014-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\youtube-videosuche.xml [2015-03-19]
FF Extension: Cache Status - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\cache@status.org [2014-05-03]
FF Extension: Chromifox Basic - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\chromifox@altmusictv.com [2013-01-29]
FF Extension: Blur (Formerly DoNotTrackMe) - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\donottrackplus@abine.com [2014-11-22]
FF Extension: FoxyProxy Standard - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\foxyproxy@eric.h.jung [2015-03-22]
FF Extension: HTTPS-Everywhere - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\https-everywhere@eff.org [2015-01-23]
FF Extension: GutscheinRausch.de - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\jl@leimbach-it.de [2013-01-29]
FF Extension: rein - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\rein@notiz.jp [2013-04-30]
FF Extension: TinEye Reverse Image Search - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\tineye@ideeinc.com [2013-01-29]
FF Extension: Forecastfox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013-01-29]
FF Extension: Elementary - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{05e38d80-09c1-11dd-bd0b-0800200c9a66} [2013-01-29]
FF Extension: Vista-aero - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{07b2a769-ed19-4483-87ce-c643914c81bb} [2013-01-29]
FF Extension: PONG! - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1368F36C-0370-419a-A408-28F94FD35974} [2013-01-29]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2013-01-29]
FF Extension: hmmXP - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{224d6e00-0336-11dd-95ff-0800200c9a66} [2013-01-29]
FF Extension: 8 Ultimo - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{2b6788a0-0ccd-11e1-be50-0800200c9a66} [2013-01-29]
FF Extension: HostIP.info Geolocation Plugin - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{49eba0b5-0393-4e13-8cc4-06298a281c5d} [2013-01-29]
FF Extension: Aero Fox XL - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66} [2013-01-29]
FF Extension: FT DeepDark - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2015-02-27]
FF Extension: W3v8 for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{7DA90D46-1B69-4cc5-9ACE-CB64D8D85B00} [2013-01-29]
FF Extension: iMacros for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2015-02-19]
FF Extension: Nightly Tester Tools - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29} [2013-11-01]
FF Extension: Proto_Dust - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{8a39fe10-f553-11dd-87af-0800200c9a66} [2013-01-29]
FF Extension: Live HTTP Headers - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2013-06-12]
FF Extension: Bamboo Feed Reader - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{b2e69492-2358-071a-7056-24ad0c3defb1} [2015-02-21]
FF Extension: Gnome - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{bdc06860-70c3-11dd-ad8b-0800200c9a66} [2013-01-29]
FF Extension: iPox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{c9c58820-7bd4-11da-a72b-0800200c9a66} [2013-01-29]
FF Extension: User Agent Switcher - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1} [2013-01-29]
FF Extension: PageZoom [de] - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{eeb299da-31d8-4683-aad4-9c9a045e0351} [2013-01-29]
FF Extension: CustomizeGoogle - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb} [2013-01-29]
FF Extension: SEOpen - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{ff6bdc07-eed6-4815-ad95-d7938b673ab5} [2013-01-29]
FF Extension: Classic Theme Restorer - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-06-16]
FF Extension: Classic Toolbar Buttons - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2014-06-19]
FF Extension: Firebug - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\firebug@software.joehewitt.com.xpi [2013-01-29]
FF Extension: Ghostery - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\firefox@ghostery.com.xpi [2015-02-24]
FF Extension: Glaze Black - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\glaze_black@www.theme-oasis.org.xpi [2013-01-29]
FF Extension: ipFuck - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\ipfuck@p4ul.info.xpi [2014-03-07]
FF Extension: Lightbeam - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2013-01-29]
FF Extension: NASA Night Launch - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\nasanightlaunch@example.com.xpi [2013-01-29]
FF Extension: Netscape Navigator Nostalgia - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\Netscape@gideas.xpi [2013-01-29]
FF Extension: Niederschlagsradar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\niederschlagsradar@sensiva.net.xpi [2013-01-29]
FF Extension: Classic Compact Options - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\notreal.ccoptions@environmentalchemistry.com.xpi [2013-01-29]
FF Extension: RightBar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\rightbar@realmtech.net.xpi [2014-06-19]
FF Extension: Secret Agent - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\SecretAgent@Dephormation.org.uk.xpi [2014-03-12]
FF Extension: Secure Login - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\secureLogin@blueimp.net.xpi [2015-02-11]
FF Extension: MZ8 - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\someone@somewhere.xpi [2014-07-27]
FF Extension: Throbber Restored - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\Throbber-Restored@jetpack.xpi [2014-09-07]
FF Extension: Flagfox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-10]
FF Extension: Image Zoom - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2013-04-16]
FF Extension: Aeon Colors - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1DEAE5AA-E19E-458b-9C8C-73CB651B9A58}.xpi [2013-01-29]
FF Extension: LittleFox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}.xpi [2014-06-20]
FF Extension: Leet Key - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{3335F91D-2AEF-4097-B831-C96C60349822}.xpi [2013-01-29]
FF Extension: Organize Status Bar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{35106bca-6c78-48c7-ac28-56df30b51d2c}.xpi [2013-01-29]
FF Extension: Qute Classic - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{5514CFC3-D9A8-4f1a-8DF1-930EBFB59901}.xpi [2013-01-29]
FF Extension: STEAM - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{678156d0-0e01-11df-8a39-0800200c9a66}.xpi [2013-01-29]
FF Extension: Nautipolis for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{6C4BAFB6-2AC2-4405-A98D-546B55B3AE92}.xpi [2013-01-29]
FF Extension: NoScript - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-01-29]
FF Extension: ReloadEvery - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2013-01-29]
FF Extension: n2scape - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{962229ad-1a31-4d4f-ac5b-a86cbc38f6bb}.xpi [2013-01-29]
FF Extension: Tamper Data - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi [2013-01-29]
FF Extension: Video DownloadHelper - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-03-06]
FF Extension: Sothink Flash Downloader for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{BAEBEF65-9289-47c5-8524-C345CC5D860D}.xpi [2013-01-29]
FF Extension: Web Developer - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2013-01-29]
FF Extension: classiccompact - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{D46E8522-6E86-44b1-A622-58C0668AD78E}.xpi [2013-01-29]
FF Extension: FOXSCAPE - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{da7f40f0-8675-11db-b606-0800200c9a66}.xpi [2013-01-29]
FF Extension: DownThemAll! - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2013-01-29]
FF Extension: Torbutton - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}.xpi [2013-01-29]
FF Extension: HackBar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{F5DDF39C-9293-4d5e-9AA8-E04E6DD5E9B4}.xpi [2013-10-05]
FF Extension: Mosaic-Fox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{f9bddc00-152b-11de-8c30-0800200c9a66}.xpi [2013-01-29]
FF Extension: Firefox 2, the theme, reloaded - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{fd2f951f-77ea-4938-9493-0c892c027a13}.xpi [2014-06-19]
FF Extension: QuickStores-Toolbar - C:\Program Files\Mozilla Firefox\extensions\quickstores@quickstores.de.xpi [2015-03-22]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-20] ()
S4 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [70952 2011-03-31] (CyberLink)
S4 CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [312616 2011-03-31] (CyberLink)
R2 DokanMounter; C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe [22736 2014-08-25] ()
S4 EMET_Service; C:\Program Files\EMET 5.1\EMET_Service.exe [31880 2014-11-09] (Microsoft Corporation)
S3 Futuremark SystemInfo Service; C:\Program Files\Futuremark\SystemInfo\FMSISvc.exe [614624 2015-02-09] (Futuremark)
S3 ICCS; C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 IswSvc; C:\Program Files\CheckPoint\AKL\AkSVC.exe [749176 2014-05-14] (Check Point Software Technologies LTD)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [238288 2015-03-23] (McAfee, Inc.)
S2 nlndis; C:\Program Files\NetLimiter Ndis Miniport Service\nlndis.exe [32768 2011-10-05] (Locktime Software) [File not signed]
S3 nlsvc; C:\Program Files\NetLimiter 3\nlsvc.exe [1126400 2013-02-20] (Locktime Software) [File not signed]
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2505160 2013-01-07] (O&O Software GmbH)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [32568 2014-08-07] (The OpenVPN Project)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1910640 2015-03-04] (Electronic Arts)
S4 Razer Game Scanner Service; C:\Program Files\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-02-05] ()
S3 Realtek87B; C:\Program Files\Realtek\RTL8187 Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed]
S3 RUBotSrv; C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe [443416 2013-07-25] (Trend Micro Inc.)
S4 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-01-14] (Crawler.com)
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 VC10SecS; C:\Program Files\Virtual CD v10\System\VC10SecS.exe [144712 2011-10-19] (H+H Software GmbH)
R2 VMAuthdService; C:\Program Files\VMware\VMware Workstation\vmware-authd.exe [86744 2014-06-12] (VMware, Inc.)
R2 VMnetDHCP; C:\Windows\system32\vmnetdhcp.exe [359128 2014-06-12] (VMware, Inc.)
R2 VMUSBArbService; C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [722624 2014-02-27] (VMware, Inc.)
R2 VMware NAT Service; C:\Windows\system32\vmnat.exe [437976 2014-06-12] (VMware, Inc.)
S2 VMwareHostd; C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe [14407384 2014-06-12] ()
S3 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3592120 2014-05-30] (Check Point Software Technologies Ltd.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [90936 2014-05-29] (Check Point Software Technologies, Ltd.)
R2 ZoneAlarm AntiTheft; C:\Program Files\CheckPoint\AntiTheft\Antitheft.exe [3128968 2014-05-30] (Check Point Software Technologies Ltd.)
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 CrystalSysInfo; C:\Program Files\MediaCoder\SysInfo.sys [15152 2007-09-25] ()
R2 Dokan; C:\Windows\system32\drivers\dokan.sys [105680 2014-08-25] (Windows (R) Win 7 DDK provider)
S3 ENTECH; C:\Windows\system32\DRIVERS\ENTECH.sys [21664 2004-10-25] (EnTech Taiwan) [File not signed]
S3 es1371; C:\Windows\System32\drivers\es1371mp.sys [40832 2002-06-03] (Creative Technology Ltd.)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
S3 GKBFltr; C:\Windows\System32\Drivers\GameKB.sys [19328 2009-12-29] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R2 hcmon; C:\Windows\system32\drivers\hcmon.sys [43840 2014-02-27] (VMware, Inc.)
S3 HH10Help.sys; C:\Windows\system32\drivers\HH10Help.sys [13952 2010-03-10] (H+H Software GmbH) [File not signed]
R0 iaStorA; C:\Windows\System32\drivers\iaStorA.sys [532536 2012-09-01] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [25656 2012-09-01] (Intel Corporation)
S3 icsak; C:\Program Files\CheckPoint\AKL\ak\icsak.sys [39296 2014-05-14] (Check Point Software Technologies LTD)
R2 ISWKL; C:\Program Files\CheckPoint\AKL\ISWKL.sys [42880 2014-05-14] (Check Point Software Technologies LTD)
R0 iusb3hcs; C:\Windows\System32\drivers\iusb3hcs.sys [16880 2013-02-22] (Intel Corporation)
R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [352752 2013-02-22] (Intel Corporation)
R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [796656 2013-02-22] (Intel Corporation)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-04-30] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [488032 2014-04-30] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2014-04-30] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [43608 2014-04-30] (Kaspersky Lab)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144352 2014-04-30] (Kaspersky Lab ZAO)
R3 MBfilt; C:\Windows\System32\drivers\MBfilt32.sys [24664 2009-11-18] (Creative Technology Ltd.)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-02] (Intel Corporation)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [648552 2015-03-23] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [91840 2015-03-23] (McAfee, Inc.)
R3 NLNdisMP; C:\Windows\System32\DRIVERS\nlndis.sys [5230088 2011-03-21] (Locktime Software)
S3 NLNdisPT; C:\Windows\System32\DRIVERS\nlndis.sys [5230088 2011-03-21] (Locktime Software)
R1 nltdi; C:\Program Files\NetLimiter 3\nltdi.sys [5281672 2011-03-21] (Locktime Software)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R2 ntk_PowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [71664 2011-04-20] (Cyberlink Corp.)
R2 ParagonLDM; C:\Windows\system32\drivers\biont_bs.sys [24512 2014-04-11] (Paragon Software GmbH)
S3 pneteth; C:\Windows\System32\DRIVERS\pneteth.sys [13440 2011-11-24] (June Fabrics Technology Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
S3 RTCore32; C:\Program Files\MSI Afterburner\RTCore32.sys [5632 2013-03-11] () [File not signed]
S3 RTL8187; C:\Windows\System32\DRIVERS\rtl8187.sys [375808 2010-01-07] (Realtek Semiconductor Corporation                          )
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [35624 2014-12-17] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [20416 2015-02-05] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [97088 2014-11-17] (Razer, Inc.)
R3 rzudd; C:\Windows\System32\DRIVERS\rzudd.sys [151336 2014-12-30] (Razer Inc)
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP2\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware)
R0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [436792 2013-01-30] () [File not signed]
R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
R0 SscRdBus; C:\Windows\System32\DRIVERS\SscRdBus.sys [88296 2014-11-22] (SuperSpeed LLC) [File not signed]
R0 SscRdCls; C:\Windows\System32\DRIVERS\SscRdCls.sys [40984 2007-12-19] (SuperSpeed LLC)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [23040 2014-04-08] (The OpenVPN Project)
S3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [5120 2012-12-19] ()
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [91016 2013-12-26] ()
R1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [20616 2013-12-26] ()
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [540168 2013-12-26] ()
S1 Uim_Vim; C:\Windows\System32\Drivers\Uim_Vim.sys [283600 2012-11-22] (Paragon)
R1 vdrv1000; C:\Windows\System32\DRIVERS\vdrv1000.sys [186392 2011-04-19] (H+H Software GmbH)
R3 vmkbd2; C:\Windows\system32\drivers\VMkbd.sys [26456 2014-06-12] (VMware, Inc.)
R3 VMnetAdapter; C:\Windows\System32\DRIVERS\vmnetadapter.sys [17104 2014-06-12] (VMware, Inc.)
R2 VMnetBridge; C:\Windows\System32\DRIVERS\vmnetbridge.sys [37456 2014-06-12] (VMware, Inc.)
R2 VMnetuserif; C:\Windows\system32\drivers\vmnetuserif.sys [26968 2014-06-12] (VMware, Inc.)
R2 vmx86; C:\Windows\system32\Drivers\vmx86.sys [66136 2014-06-12] (VMware, Inc.)
R3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [172416 2010-11-20] (Microsoft Corporation)
R1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [48128 2010-11-20] (Microsoft Corporation)
R3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2010-11-20] (Microsoft Corporation)
R1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [296064 2010-11-20] (Microsoft Corporation)
R1 Vsdatant; C:\Windows\System32\drivers\vsdatant.sys [456088 2014-05-30] (Check Point Software Technologies Ltd.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [63824 2013-10-08] (VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\System32\drivers\vstor2-mntapi20-shared.sys [23632 2013-02-22] (VMware, Inc.)
R2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam.sys [1068216 2012-04-15] (Windows (R) Win 7 DDK provider)
R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22856 2010-04-27] (Logitech Inc.)
S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [37704 2010-04-27] (Logitech Inc.)
S3 WmHidLo; C:\Windows\System32\drivers\WmHidLo.sys [31816 2010-04-27] (Logitech Inc.)
R3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [15048 2010-04-27] (Logitech Inc.)
R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66632 2010-04-27] (Logitech Inc.)
S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [465408 2009-07-14] (Microsoft Corporation)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [77296 2011-04-12] (CyberLink Corp.)
S3 catchme; \??\C:\Users\HAKENN~1\AppData\Local\Temp\catchme.sys [X]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2014-04-30] (Kaspersky Lab ZAO)
S4 NvStUSB; \SystemRoot\system32\drivers\nvstusb.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-23 09:32 - 2015-03-23 09:33 - 00000000 ____D () C:\Program Files\MiniTool Partition Wizard Free 9.0
2015-03-23 09:32 - 2015-03-23 09:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard Free 9.0
2015-03-23 08:20 - 2015-03-23 08:20 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-03-23 06:22 - 2015-03-23 06:22 - 00648552 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfehidk.sys
2015-03-23 06:22 - 2015-03-23 06:22 - 00238288 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe
2015-03-23 06:22 - 2015-03-23 06:22 - 00091840 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mferkdet.sys
2015-03-23 03:20 - 2015-03-25 07:46 - 00000000 ____D () C:\Windows\erdnt
2015-03-23 03:07 - 2015-03-25 07:57 - 00000000 ____D () C:\FRST
2015-03-23 02:18 - 2015-03-23 09:37 - 00172576 _____ () C:\Users\Friedrich\Documents\pinfect.zip
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\VDLL.DLL
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\system32\runouce.exe
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\RUNDL132.EXE
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\logo_1.exe
2015-03-23 00:29 - 2015-03-23 09:36 - 00000054 _____ () C:\Windows\Lic.xxx
2015-03-23 00:29 - 2015-03-23 00:29 - 00034048 _____ (MicroWorld Technologies Inc.) C:\Windows\system32\eEmpty.exe
2015-03-23 00:29 - 2015-03-23 00:29 - 00000000 ____D () C:\ProgramData\MicroWorld
2015-03-23 00:29 - 2015-03-23 00:29 - 00000000 ____D () C:\Program Files\Common Files\MicroWorld
2015-03-23 00:29 - 2005-09-22 23:22 - 00000522 _____ () C:\Windows\system32\Microsoft.VC80.CRT.manifest
2015-03-23 00:22 - 2015-03-25 06:58 - 00000000 ____D () C:\Users\Friedrich\Desktop\Sammlung fürs Board
2015-03-22 20:37 - 2015-03-22 20:37 - 00000000 ____D () C:\ProgramData\Trend Micro
2015-03-22 20:25 - 2015-03-22 20:28 - 00000353 _____ () C:\Users\Friedrich\Desktop\Office AUTOKMS sehr Wichtig.txt
2015-03-22 19:00 - 2015-03-22 19:00 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-03-22 18:29 - 2015-03-22 18:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-20 23:13 - 2015-03-20 23:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro RUBotted
2015-03-20 23:13 - 2015-03-20 23:13 - 00000000 ____D () C:\Program Files\Trend Micro
2015-03-20 22:57 - 2015-03-20 22:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft HiJackFree
2015-03-20 22:57 - 2015-03-20 22:57 - 00000000 ____D () C:\Program Files\Emsisoft HiJackFree
2015-03-20 22:56 - 2015-03-20 22:56 - 02925920 _____ (Emsisoft GmbH ) C:\Users\Friedrich\Desktop\EmsisoftHiJackFreeSetup.exe
2015-03-20 22:47 - 2015-03-20 22:51 - 140425968 _____ (Microsoft Corporation) C:\Users\Friedrich\Desktop\Microsoft Security Scanner.exe
2015-03-20 19:07 - 2015-03-20 19:11 - 00000000 ____D () C:\TDSSKiller_Quarantine
2015-03-19 01:28 - 2015-03-19 02:52 - 00000000 ____D () C:\Users\Friedrich\Desktop\ThinkpadpunkteVideo
2015-03-19 00:53 - 2015-03-22 19:01 - 00429152 _____ () C:\Users\Friedrich\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-19 00:52 - 2015-03-22 19:12 - 04703120 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-19 00:18 - 2015-03-19 00:20 - 00084562 _____ () C:\Users\Friedrich\Desktop\usbdeview.zip
2015-03-19 00:18 - 2015-03-19 00:20 - 00046516 _____ () C:\Users\Friedrich\Desktop\driverview.zip
2015-03-19 00:17 - 2015-03-19 00:20 - 00068998 _____ () C:\Users\Friedrich\Desktop\bluescreenview.zip
2015-03-18 21:39 - 2015-03-18 21:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GNavigia
2015-03-18 21:39 - 2010-04-07 02:29 - 00081920 _____ () C:\Windows\system32\GkSui20.EXE
2015-03-18 21:26 - 2015-03-18 21:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2015-03-18 21:26 - 2015-03-16 18:44 - 00749664 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2015-03-18 21:25 - 2015-03-18 21:25 - 00000000 ____D () C:\Program Files\Oracle
2015-03-18 21:25 - 2015-03-16 18:42 - 00104384 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2015-03-18 21:17 - 2015-03-18 21:17 - 00000000 ____D () C:\Windows\system32\RTCOM
2015-03-18 21:16 - 2014-12-03 13:51 - 00927960 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll
2015-03-18 21:16 - 2014-12-03 11:41 - 03365208 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys
2015-03-18 21:16 - 2014-12-03 10:15 - 01485163 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2015-03-18 21:16 - 2014-12-02 11:42 - 02381680 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll
2015-03-18 21:16 - 2014-11-27 08:31 - 02510192 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO.dll
2015-03-18 21:16 - 2014-08-06 06:43 - 02588888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll
2015-03-18 21:16 - 2014-04-10 05:19 - 01940056 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2015-03-18 21:16 - 2014-03-06 09:35 - 01892056 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl
2015-03-18 21:16 - 2014-02-18 10:04 - 02421792 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2015-03-18 21:16 - 2014-01-08 08:25 - 00332568 _____ (Creative Technology Ltd.) C:\Windows\system32\MBWrp32.dll
2015-03-18 21:16 - 2013-01-11 09:27 - 00563992 _____ (Creative Technology Ltd.) C:\Windows\system32\MBTHX32.dll
2015-03-18 21:16 - 2011-11-22 09:28 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT32.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA32.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG32A.dll
2015-03-18 21:16 - 2010-09-27 02:34 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2015-03-18 21:16 - 2009-12-04 08:43 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSXT.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSHD.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP360.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW.dll
2015-03-18 21:16 - 2009-11-18 11:42 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesLib.dll
2015-03-18 21:16 - 2009-11-18 00:12 - 00024664 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\MBfilt32.sys
2015-03-18 21:15 - 2014-06-06 17:00 - 00519368 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll
2015-03-18 21:15 - 2013-10-11 05:47 - 00092584 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-03-18 21:15 - 2012-03-08 04:47 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll
2015-03-18 20:49 - 2015-01-25 11:20 - 00000000 ____D () C:\Users\Friedrich\Desktop\Baphomets Fluch 1-5 Deutsch
2015-03-17 14:44 - 2015-03-18 17:10 - 329252864 _____ () C:\Users\Friedrich\Desktop\openSUSE-13.2-DVD-i586.iso
2015-03-17 14:37 - 2015-03-17 14:41 - 79691776 _____ () C:\Users\Friedrich\Desktop\CorePlus-current.iso
2015-03-16 18:42 - 2015-03-16 18:42 - 00115672 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetAdp.sys
2015-03-12 15:27 - 2015-03-25 06:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Everything
2015-03-12 15:27 - 2015-03-12 15:27 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Everything
2015-03-11 20:41 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-03-11 20:41 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-03-11 20:41 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2015-03-11 20:02 - 2015-03-06 06:15 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-11 20:02 - 2015-03-06 06:15 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-11 20:02 - 2015-03-06 06:10 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-11 20:02 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-11 20:02 - 2015-03-06 06:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-11 20:02 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-11 20:02 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-11 20:02 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-11 20:02 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 20:02 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 20:02 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 20:02 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 20:02 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 20:02 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 20:02 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 20:02 - 2015-02-20 03:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 20:02 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 20:02 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-11 20:02 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-11 20:02 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 20:02 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 20:02 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 20:02 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-11 20:02 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-11 20:02 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 20:02 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 20:02 - 2015-02-20 02:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-11 20:02 - 2015-02-20 02:50 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 20:02 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 20:02 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-11 20:02 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 20:02 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 20:02 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 20:02 - 2015-02-20 02:24 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-11 20:02 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-11 20:02 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 20:02 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 20:02 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 20:02 - 2015-01-31 00:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-11 20:02 - 2015-01-29 04:05 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-03-11 20:02 - 2015-01-29 04:05 - 03917752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-11 20:02 - 2015-01-29 04:01 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-11 20:02 - 2015-01-29 04:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-11 20:02 - 2015-01-29 03:57 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-11 20:01 - 2015-02-26 04:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 20:01 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 20:01 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 20:01 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 20:01 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 20:01 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 20:01 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 20:01 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 20:00 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-03-11 17:12 - 2015-03-11 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PY Software
2015-03-11 17:12 - 2007-08-13 14:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\wmvdmoe.dll
2015-03-11 16:57 - 2015-03-11 17:03 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\WebcamZoneTrigger
2015-03-11 16:12 - 2015-03-11 16:12 - 00000000 ____D () C:\Users\Public\Documents\Xeoma
2015-03-11 12:19 - 2015-03-11 12:19 - 00000000 ____D () C:\Windows\system32\DCS
2015-03-11 01:10 - 2015-03-11 01:10 - 00003584 _____ () C:\Users\Friedrich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-08 10:55 - 2015-03-08 10:55 - 06208736 _____ (Tim Kosse) C:\Users\Friedrich\Downloads\FileZilla_3.10.2_win32-setup.exe
2015-03-08 10:55 - 2015-03-08 10:55 - 06057862 _____ (Tim Kosse) C:\Users\Friedrich\Downloads\FileZilla_3.9.0.5_win32-setup.exe
2015-03-08 03:47 - 2015-03-08 03:47 - 00000216 _____ () C:\Users\Friedrich\Desktop\rFactor Demo.url
2015-03-08 02:07 - 2015-03-08 02:07 - 00000623 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LEGO Batman 3 - Beyond Gotham.lnk
2015-03-08 02:02 - 2015-03-08 02:02 - 00000000 ____D () C:\Program Files\LEGO Batman 3 - Beyond Gotham
2015-03-06 05:12 - 2015-03-06 05:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Apple Computer
2015-03-06 05:10 - 2015-03-06 05:12 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-03-06 05:10 - 2015-03-06 05:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-03-06 05:08 - 2015-03-21 19:35 - 00000000 ____D () C:\Users\Friedrich\Desktop\LightWorks DE Tutorials
2015-03-06 04:28 - 2015-03-06 04:28 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-03-05 21:53 - 2015-03-05 21:53 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Stardock
2015-03-05 20:41 - 2015-03-13 19:42 - 00000000 ____D () C:\Users\Friedrich\Desktop\Chromanova.fm  - crazy freak dance 24-7-
2015-03-05 07:50 - 2015-03-05 07:50 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\com.ohnoo.TormentumDemo
2015-03-05 07:31 - 2015-03-05 07:31 - 00000000 ____D () C:\Users\Friedrich\Documents\SpriteLamp
2015-03-05 07:31 - 2015-03-05 07:31 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\SpriteLampWinforms
2015-03-05 06:58 - 2015-03-05 07:03 - 00000000 ____D () C:\Program Files\TClock
2015-03-05 06:04 - 2015-03-05 06:04 - 00000000 ____D () C:\Windows Anmeldesounds +Icons AlleSys Bildschirmschoner
2015-03-05 05:49 - 2015-03-05 05:49 - 00000000 ____D () C:\ProgramData\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 __HDC () C:\ProgramData\{9C3F823B-4738-4CAF-A6B2-69E87FB636C0}
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\Users\Public\Documents\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\Program Files\Stardock
2015-03-05 05:28 - 2015-03-05 05:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPU
2015-03-05 05:28 - 2015-03-05 05:28 - 00000000 ____D () C:\Program Files\MPU
2015-03-05 05:20 - 2015-03-05 05:20 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Lern-o-Mat
2015-03-05 05:14 - 2015-03-05 05:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD-lab PRO 2.0
2015-03-05 05:14 - 2015-03-05 05:14 - 00000000 ____D () C:\Program Files\DVDlabPro2
2015-03-05 05:13 - 2015-03-05 05:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Doc Scrubber
2015-03-05 05:13 - 2015-03-05 05:13 - 00000000 ____D () C:\Program Files\Doc Scrubber
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\jStrip
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jStrip
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\Program Files\jStrip
2015-03-05 05:12 - 1999-10-30 02:00 - 00167936 _____ (Common Controls Replacement Project (CCRP)) C:\Windows\system32\ccrpftv6.ocx
2015-03-04 06:03 - 2015-03-12 12:34 - 00000000 ____D () C:\Users\Friedrich\.mediathek3
2015-03-04 06:03 - 2015-03-04 06:03 - 00000000 ____D () C:\Program Files\Mediathekview
2015-03-03 19:32 - 2015-03-03 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2015-03-03 19:32 - 2015-03-03 19:32 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2015-03-03 18:52 - 2015-03-03 18:54 - 63361024 _____ () C:\Users\Friedrich\Desktop\EpicGamesLauncherInstaller-2.0.0-2465596.msi
2015-03-03 18:13 - 2015-03-03 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
2015-03-02 07:05 - 2015-03-02 07:05 - 00000000 ____D () C:\Users\Friedrich\Documents\Bandicam
2015-03-02 07:04 - 2015-03-23 16:41 - 00000000 ____D () C:\Program Files\Bandicam
2015-03-02 07:04 - 2015-03-02 07:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2015-03-02 07:04 - 2015-03-02 07:04 - 00000000 ____D () C:\Program Files\BandiMPEG1
2015-03-01 23:52 - 2015-03-01 23:52 - 00000000 ____D () C:\Users\Friedrich\Desktop\Silent Hill Downpour (Xbox 360 Gamerip)
2015-02-28 18:06 - 2015-02-05 18:51 - 00621384 _____ (NVIDIA Corporation) C:\Windows\system32\nvStreaming.exe
2015-02-28 18:05 - 2015-02-05 21:48 - 24768144 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 20465808 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 16016848 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 10773520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 10713256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 08473928 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-02-28 18:05 - 2015-02-05 21:48 - 03247248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 01047880 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3234752.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00931136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00912528 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3234752.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00909120 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00877816 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshim.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00399504 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00345928 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00305136 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim32.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00164568 _____ (NVIDIA Corporation) C:\Windows\system32\nvinit.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00161424 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda32v.sys
2015-02-28 18:05 - 2015-02-05 21:48 - 00027280 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap32.dll
2015-02-27 16:04 - 2015-02-27 19:00 - 00000000 ____D () C:\Program Files\EMET 5.1
2015-02-27 16:04 - 2015-02-27 16:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit
2015-02-27 03:00 - 2015-02-27 03:00 - 00000216 _____ () C:\Users\Friedrich\Desktop\Tormentum - Dark Sorrow Demo.url
2015-02-26 18:36 - 2015-02-26 18:36 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cain
2015-02-26 18:36 - 2015-02-26 18:36 - 00000000 ____D () C:\Program Files\Cain
2015-02-24 19:24 - 2015-03-20 23:09 - 00000000 ____D () C:\Users\Friedrich\Documents\Survarium

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-25 07:57 - 2013-01-30 06:57 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\NetSpeedMonitor
2015-03-25 07:57 - 2013-01-30 01:23 - 00000000 ____D () C:\Users\Friedrich\Desktop\Sicherheitsprogramme
2015-03-25 07:46 - 2010-11-20 22:01 - 01639348 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-25 07:46 - 2009-07-14 05:34 - 00034848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-25 07:46 - 2009-07-14 05:34 - 00034848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-25 07:42 - 2013-01-29 18:50 - 01286151 _____ () C:\Windows\WindowsUpdate.log
2015-03-25 07:39 - 2013-02-17 07:38 - 00000000 ____D () C:\ProgramData\VMware
2015-03-25 07:38 - 2014-07-03 02:07 - 00067682 _____ () C:\Windows\setupact.log
2015-03-25 07:38 - 2014-01-11 03:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-03-25 07:38 - 2013-01-30 08:01 - 01846372 _____ () C:\Windows\system32\oodbs.lor
2015-03-25 07:38 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-25 07:37 - 2014-07-05 01:31 - 00000000 ____D () C:\AdwCleaner
2015-03-25 06:56 - 2014-11-15 20:35 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-25 06:54 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Registration
2015-03-25 04:44 - 2013-01-30 05:14 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\CrashDumps
2015-03-23 20:27 - 2013-03-02 16:35 - 00000000 ____D () C:\Program Files\Pluto Client
2015-03-23 20:15 - 2014-07-05 01:41 - 00607496 _____ () C:\Windows\PFRO.log
2015-03-23 20:12 - 2014-01-11 01:33 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Apps\2.0
2015-03-23 20:12 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2015-03-23 20:08 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2015-03-23 16:50 - 2013-02-11 06:02 - 00000000 ____D () C:\Users\Friedrich\Desktop\Magic.Games.II
2015-03-23 16:41 - 2013-01-30 06:17 - 00000000 ____D () C:\Program Files\mIRC
2015-03-23 16:39 - 2013-02-18 03:52 - 00000000 ____D () C:\Program Files\Dead Space 3 Limited Edition uncut
2015-03-23 16:39 - 2013-02-09 08:44 - 00000000 ____D () C:\Program Files\Magic The Gathering - Duels of the Planeswalkers
2015-03-23 16:39 - 2013-02-04 05:20 - 00000000 ____D () C:\Program Files\Serials World
2015-03-23 16:38 - 2014-01-29 18:03 - 00000000 ____D () C:\Program Files\DLH98
2015-03-23 16:37 - 2013-01-31 03:54 - 00000000 ____D () C:\Program Files\DiRT 3
2015-03-23 16:34 - 2014-07-06 04:05 - 00000000 ____D () C:\Program Files\Assetto Corsa
2015-03-23 16:34 - 2013-02-11 03:53 - 00000000 ____D () C:\Program Files\Ricochet Infinity
2015-03-23 16:33 - 2014-06-12 00:18 - 00000000 ____D () C:\Program Files\HD Video Repair Utility
2015-03-23 16:33 - 2013-03-02 16:32 - 00000000 ____D () C:\Program Files\Portrait Professional Studio 9
2015-03-23 08:21 - 2013-01-30 01:31 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\KeePass
2015-03-23 08:21 - 2013-01-30 01:20 - 00042334 _____ () C:\Users\Friedrich\NeueDatenbank.kdbx
2015-03-23 08:21 - 2013-01-29 18:50 - 00000000 ____D () C:\Users\Friedrich
2015-03-23 07:02 - 2013-02-05 00:25 - 00000000 ____D () C:\Program Files\stinger
2015-03-23 06:21 - 2013-06-04 01:27 - 00000000 ____D () C:\Stinger_Quarantine
2015-03-23 06:15 - 2014-03-23 15:43 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-03-23 06:00 - 2014-03-23 15:42 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-23 05:25 - 2013-01-30 04:08 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\vlc
2015-03-23 04:16 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-03-23 03:38 - 2009-07-14 05:53 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-23 02:47 - 2014-11-16 21:36 - 00000000 ____D () C:\Program Files\Spezial 5.0
2015-03-22 22:33 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-03-22 22:10 - 2013-01-30 01:23 - 00000000 ____D () C:\Users\Friedrich\Desktop\Weitere Programme
2015-03-22 21:36 - 2013-01-30 06:18 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\NoNameScript
2015-03-22 20:24 - 2014-10-20 17:53 - 00000000 ____D () C:\ProgramData\GalaxyClient
2015-03-22 19:59 - 2013-01-30 06:17 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\mIRC
2015-03-22 19:03 - 2013-11-22 18:50 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\AIMP3
2015-03-22 19:03 - 2013-01-30 03:24 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-22 18:56 - 2014-05-14 17:55 - 00000000 ____D () C:\Users\Friedrich\Desktop\Rap Mai 2014
2015-03-22 18:44 - 2013-02-06 04:46 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-22 18:23 - 2014-02-07 14:18 - 00000600 _____ () C:\Users\Friedrich\AppData\Roaming\winscp.rnd
2015-03-22 18:10 - 2014-08-20 05:17 - 00000000 ____D () C:\Windows\Minidump
2015-03-21 06:12 - 2013-01-30 05:49 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-03-20 22:23 - 2013-02-06 02:07 - 00000000 ____D () C:\Temp
2015-03-20 21:39 - 2013-01-30 06:49 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2015-03-20 19:34 - 2014-05-04 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WhoCrashed
2015-03-20 19:34 - 2014-05-04 18:34 - 00000000 ____D () C:\Program Files\WhoCrashed
2015-03-20 18:06 - 2013-02-01 15:18 - 00000000 ____D () C:\Program Files\Vuze
2015-03-19 07:56 - 2013-01-29 23:12 - 00000000 ____D () C:\Windows\pss
2015-03-19 06:48 - 2013-03-25 17:56 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\NPE
2015-03-19 03:53 - 2013-01-30 08:07 - 00000000 ____D () C:\Program Files\Steam
2015-03-19 02:39 - 2013-03-04 20:10 - 00000000 ____D () C:\Program Files\KaloMa
2015-03-19 00:48 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-03-19 00:26 - 2014-06-16 02:02 - 00064681 ____H () C:\Windows\system32\BTImages.dat
2015-03-19 00:25 - 2013-01-25 15:30 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-03-19 00:21 - 2013-02-04 05:24 - 00000000 ____D () C:\Program Files\USB Deview
2015-03-19 00:20 - 2014-09-14 21:01 - 00000000 ____D () C:\Program Files\Bluescreen View
2015-03-19 00:20 - 2014-02-14 02:24 - 00000000 ____D () C:\Program Files\DriverView v1.45
2015-03-18 22:11 - 2013-07-16 15:55 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\FileZilla
2015-03-18 21:27 - 2014-02-24 06:30 - 00000000 ____D () C:\Users\Friedrich\.VirtualBox
2015-03-18 21:17 - 2013-01-25 15:37 - 00000000 ___HD () C:\Program Files\Temp
2015-03-18 21:04 - 2013-02-01 15:18 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Azureus
2015-03-18 18:45 - 2013-02-17 08:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\VMware
2015-03-18 18:45 - 2013-02-17 08:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\VMware
2015-03-16 21:48 - 2013-01-30 01:16 - 00000000 ____D () C:\Users\Friedrich\Mädels u. Chatter
2015-03-16 14:56 - 2015-02-09 11:04 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\.Tribler
2015-03-15 13:50 - 2013-01-31 03:07 - 00000000 ____D () C:\Program Files\Trillian
2015-03-14 17:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2015-03-12 16:44 - 2014-08-17 15:52 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Adobe
2015-03-12 16:44 - 2013-01-29 22:44 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-12 16:44 - 2013-01-29 22:44 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-12 15:27 - 2013-02-01 15:44 - 00000000 ____D () C:\Program Files\Search Everything
2015-03-12 15:24 - 2013-03-19 12:11 - 00000000 ____D () C:\Windows\system32\MAGIX
2015-03-12 15:19 - 2013-01-30 02:18 - 00000000 ____D () C:\Users\Friedrich\Desktop\Spiele
2015-03-12 01:23 - 2013-02-01 16:32 - 00000000 ____D () C:\ProgramData\Origin
2015-03-11 20:42 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-03-11 20:32 - 2014-02-19 19:09 - 00000000 ___RD () C:\Users\Friedrich\Virtual Machines
2015-03-11 20:17 - 2013-08-03 23:48 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-11 15:19 - 2013-01-29 22:28 - 00007655 _____ () C:\Users\Friedrich\AppData\Local\Resmon.ResmonCfg
2015-03-11 13:36 - 2014-07-24 00:39 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\.minecraft
2015-03-11 13:26 - 2013-02-07 04:13 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Razer
2015-03-11 13:26 - 2013-02-07 04:12 - 00000000 ____D () C:\ProgramData\Razer
2015-03-11 13:26 - 2013-01-30 05:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-03-11 13:26 - 2013-01-30 05:03 - 00000000 ____D () C:\Program Files\Razer
2015-03-11 12:11 - 2013-08-21 03:42 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\midori
2015-03-11 02:35 - 2013-02-06 02:14 - 00000000 ____D () C:\ProgramData\TEMP
2015-03-10 04:18 - 2014-06-24 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SRWare Iron
2015-03-10 04:18 - 2014-06-24 16:21 - 00000000 ____D () C:\Program Files\SRWare Iron
2015-03-09 09:57 - 2013-04-11 01:04 - 00000000 ____D () C:\Program Files\SpeedFan
2015-03-09 08:08 - 2014-08-23 16:30 - 00000000 ____D () C:\Users\Friedrich\Desktop\New Handy Root und ähnliches Tutorials
2015-03-08 10:56 - 2013-07-16 15:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-03-08 10:56 - 2013-07-16 15:55 - 00000000 ____D () C:\Program Files\FileZilla FTP Client
2015-03-08 04:48 - 2014-01-22 17:33 - 00000000 ____D () C:\Users\Friedrich\.dbus-keyrings
2015-03-08 04:25 - 2014-07-15 21:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live
2015-03-08 04:25 - 2014-07-15 21:51 - 00000000 ____D () C:\Program Files\GameforgeLive
2015-03-08 03:47 - 2014-04-09 00:13 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-03-08 02:35 - 2013-11-19 10:19 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Warner Bros. Interactive Entertainment
2015-03-06 05:11 - 2013-02-14 06:50 - 00000000 ____D () C:\Program Files\QuickTime
2015-03-06 04:28 - 2013-09-19 21:42 - 00000000 ____D () C:\ProgramData\Oracle
2015-03-06 04:25 - 2014-01-15 06:51 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-03-06 04:25 - 2013-03-05 05:07 - 00000000 ____D () C:\Program Files\Java
2015-03-05 08:01 - 2013-08-13 00:14 - 00000000 ____D () C:\Users\Friedrich\Documents\3DMark
2015-03-05 07:58 - 2014-06-16 05:52 - 00000022 _____ () C:\Windows\GPU-Z.INI
2015-03-05 07:04 - 2013-01-29 23:29 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-03-05 07:04 - 2013-01-29 23:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-03-05 05:28 - 2013-02-05 07:26 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2015-03-05 05:11 - 2013-02-07 01:16 - 00000000 ____D () C:\Westwood
2015-03-05 05:10 - 2013-02-07 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Westwood
2015-03-05 03:01 - 2014-04-11 03:10 - 00000000 ____D () C:\Program Files\prime95 v279
2015-03-05 02:40 - 2015-02-11 15:43 - 00000000 ____D () C:\Users\Friedrich\Desktop\Spionaufnahmen mit LifeCam
2015-03-05 02:18 - 2015-02-12 12:20 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\GetRight
2015-03-04 05:16 - 2014-03-11 20:56 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\MPC-HC
2015-03-04 01:56 - 2013-02-01 16:32 - 00000000 ____D () C:\Program Files\Origin
2015-03-04 00:57 - 2013-07-24 22:30 - 00000000 ____D () C:\HammerAutosave
2015-03-03 18:13 - 2013-11-22 18:50 - 00000000 ____D () C:\Program Files\AIMP3
2015-03-02 18:21 - 2013-01-30 02:15 - 00000000 ____D () C:\Users\Friedrich\Desktop\Ernährung u Sportinfos zusatz zur MAPPE
2015-03-02 02:15 - 2013-02-26 18:36 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Audacity
2015-03-02 02:11 - 2013-02-26 18:36 - 00001000 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-03-02 02:11 - 2013-02-26 18:36 - 00000000 ____D () C:\Program Files\Audacity
2015-03-01 23:47 - 2015-02-12 12:21 - 00000000 ____D () C:\ProgramData\GetRight
2015-02-28 19:33 - 2013-02-03 00:02 - 02712576 _____ () C:\Users\Friedrich\AppData\Local\file__0.localstorage
2015-02-28 18:06 - 2013-01-25 15:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-02-28 17:10 - 2013-05-10 04:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IsoBuster
2015-02-28 17:10 - 2013-05-10 04:41 - 00000000 ____D () C:\Program Files\IsoBuster
2015-02-27 17:38 - 2013-01-30 01:44 - 00000000 ____D () C:\Users\Friedrich\Desktop\Canon Shots
2015-02-27 16:52 - 2013-02-01 16:51 - 00000000 ____D () C:\Program Files\Futuremark
2015-02-27 16:03 - 2013-01-30 02:17 - 00000000 ____D () C:\Users\Friedrich\Desktop\POP-RADIO FAKE ACCOUNTS
2015-02-27 03:26 - 2013-02-26 18:48 - 00000000 ____D () C:\Users\Public\Documents\Lightworks
2015-02-27 03:20 - 2013-02-26 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightworks
2015-02-27 03:20 - 2013-02-26 18:48 - 00000000 ____D () C:\Program Files\Lightworks
2015-02-26 21:20 - 2011-04-28 16:10 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-26 18:36 - 2013-09-04 05:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cain
2015-02-25 03:10 - 2014-06-28 07:22 - 00000000 ____D () C:\Users\Friedrich\Documents\EthanMeteorHunterDemo
2015-02-25 01:15 - 2013-01-30 01:16 - 00000000 ____D () C:\Users\Friedrich\Martin Krüger
2015-02-25 01:14 - 2013-05-24 01:11 - 00000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe PNG Format CS5 Prefs
2015-02-24 16:48 - 2013-01-29 23:37 - 00000000 ____D () C:\Program Files\CCleaner

==================== Files in the root of some directories =======

2013-10-28 21:15 - 2013-07-08 17:34 - 2699264 _____ (wPrime) C:\Program Files\wPrime.exe
2014-04-26 21:08 - 2014-04-26 21:08 - 0000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe GIF Format CS5 Prefs
2013-05-24 01:11 - 2015-02-25 01:14 - 0000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe PNG Format CS5 Prefs
2013-08-06 07:11 - 2014-10-31 04:40 - 0000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe Targa Format CS5 Prefs
2015-02-03 18:40 - 2015-02-04 21:05 - 0000623 _____ () C:\Users\Friedrich\AppData\Roaming\All CPU MeterV3_Settings.ini
2013-03-04 20:09 - 2014-02-28 15:35 - 0000540 _____ () C:\Users\Friedrich\AppData\Roaming\AutoGK.ini
2013-05-22 21:43 - 2013-08-25 04:47 - 0000000 _____ () C:\Users\Friedrich\AppData\Roaming\bfe_cddrives
2015-02-04 01:26 - 2015-02-04 01:26 - 0001002 _____ () C:\Users\Friedrich\AppData\Roaming\Currency Meter_Settings.ini
2015-02-04 01:27 - 2015-02-04 01:28 - 0000841 _____ () C:\Users\Friedrich\AppData\Roaming\Drives Meter_Settings.ini
2015-02-03 19:19 - 2015-02-03 19:21 - 0000310 _____ () C:\Users\Friedrich\AppData\Roaming\Earthquakes Meter_Settings.ini
2014-04-20 21:35 - 2015-02-03 17:31 - 0000284 _____ () C:\Users\Friedrich\AppData\Roaming\GPU MeterV2_Settings.ini
2013-06-01 08:16 - 2013-09-22 08:28 - 0001870 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile0.dat
2013-06-01 08:16 - 2013-09-22 08:28 - 0001872 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile1.dat
2013-06-01 08:16 - 2013-09-22 08:28 - 0001876 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile2.dat
2013-09-22 08:27 - 2013-09-22 08:28 - 0001832 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile3.dat
2015-02-04 01:30 - 2015-02-04 01:30 - 0001209 _____ () C:\Users\Friedrich\AppData\Roaming\Network Meter_Settings.ini
2015-02-04 01:30 - 2015-02-04 01:30 - 0000008 _____ () C:\Users\Friedrich\AppData\Roaming\Network Meter_Usage.ini
2013-02-18 05:16 - 2014-07-16 01:03 - 0138904 _____ () C:\Users\Friedrich\AppData\Roaming\PnkBstrK.sys
2014-04-18 16:25 - 2014-07-02 10:13 - 14315520 _____ () C:\Users\Friedrich\AppData\Roaming\Sandra.mdb
2014-02-07 14:18 - 2015-03-22 18:23 - 0000600 _____ () C:\Users\Friedrich\AppData\Roaming\winscp.rnd
2013-11-15 04:48 - 2013-11-15 05:13 - 0001456 _____ () C:\Users\Friedrich\AppData\Local\Adobe Für Web speichern 12.0 Prefs
2013-10-29 18:14 - 2013-10-29 18:14 - 0242095 _____ () C:\Users\Friedrich\AppData\Local\ars.cache
2013-10-29 18:14 - 2013-10-29 18:14 - 0377163 _____ () C:\Users\Friedrich\AppData\Local\census.cache
2015-03-11 01:10 - 2015-03-11 01:10 - 0003584 _____ () C:\Users\Friedrich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-02-03 00:02 - 2015-02-28 19:33 - 2712576 _____ () C:\Users\Friedrich\AppData\Local\file__0.localstorage
2013-10-29 17:44 - 2013-10-29 17:44 - 0000036 _____ () C:\Users\Friedrich\AppData\Local\housecall.guid.cache
2014-02-09 23:50 - 2014-06-27 05:58 - 0000600 _____ () C:\Users\Friedrich\AppData\Local\PUTTY.RND
2015-02-02 18:15 - 2015-02-02 18:15 - 0000733 _____ () C:\Users\Friedrich\AppData\Local\recently-used.xbel
2013-01-29 22:28 - 2015-03-11 15:19 - 0007655 _____ () C:\Users\Friedrich\AppData\Local\Resmon.ResmonCfg
2013-03-19 12:49 - 2013-03-19 12:52 - 0000041 ___SH () C:\ProgramData\.zreglib

Files to move or delete:
====================
C:\Users\Friedrich\Bsb.exe
C:\Users\Friedrich\cc_20140124_180349.reg
C:\Users\Friedrich\cc_20140315_160443.reg
C:\Users\Friedrich\cc_20140718_151624.reg
C:\Users\Friedrich\cc_20140905_190648.reg
C:\Users\Friedrich\cc_20141008_060204.reg
C:\Users\Friedrich\IP_Log_Data.js
C:\Users\Friedrich\regsicherung.reg
C:\Users\Friedrich\Sicherung reg von CCleaner 2.reg


Some content of TEMP:
====================
C:\Users\Friedrich\AppData\Local\Temp\Quarantine.exe
C:\Users\Friedrich\AppData\Local\Temp\sqlite3.dll


Some zero byte size files/folders:
==========================
C:\Windows\logo_1.exe
C:\Windows\RUNDL132.EXE
C:\Windows\VDLL.DLL
C:\Windows\System32\runouce.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-20 19:59

==================== End Of Log ============================

--- --- ---

Friedrich_ 25.03.2015 09:29

re5
 
Liste der Anhänge anzeigen (Anzahl: 1)
FRST Addition-LOG
Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by Friedrich at 2015-03-25 07:57:50
Running from C:\Users\Friedrich\Desktop\Sicherheitsprogramme
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: ZoneAlarm Extreme Security Anti-Spyware (Disabled - Up to date) {98D733EE-E4E4-BC7B-FCCD-3C9EA3D3AC14}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Extreme Security Firewall (Disabled) {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

«City Car Driving»  Releases 1.3.2 (HKLM\...\{CC457F3D-5CDE-4CE8-9685-90A4EDE81374}_is1) (Version: 1.3.2 - Forward Development)
007 Legends 1.0.2 (HKLM\...\007 Legends 1.0.2) (Version: 1.0.2 - Activision Publishing)
3DMark (HKLM\...\{1f6ed41c-36d8-4cb3-82f4-cf7b25f60143}) (Version: 1.4.775.0 - Futuremark)
3DMark (Version: 1.4.775.0 - Futuremark) Hidden
3DMark 11 (HKLM\...\{f9e83b9c-ab7e-4005-8f32-4ea69703a5e4}) (Version: 1.0.132.0 - Futuremark)
3DMark 11 (Version: 1.0.132.0 - Futuremark) Hidden
3DMark03 (HKLM\...\{FF35F637-72B9-43BE-A281-06EB2854393A}) (Version: 3.6.0 - )
ACE COMBAT ASSAULT HORIZON Enhanced Edition (HKLM\...\ACE COMBAT ASSAULT HORIZON Enhanced Edition_is1) (Version:  - )
Active@ DVD Eraser v 1.1 (HKLM\...\Active@ DVD Eraser v 1.1) (Version:  - )
Activision(R) (Version: 1.00.0000 - Activision) Hidden
Adobe AIR (HKLM\...\Adobe AIR) (Version: 14.0.0.110 - Adobe Systems Incorporated)
Adobe Community Help (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Media Player (HKLM\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Photoshop CS5 (HKLM\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)
Adrenaline Sniper Elite V2 Benchmark Tool 1.0 (Build 1.0.0.1) (HKLM\...\Adrenaline Sniper Elite V2 Benchmark Tool_is1) (Version:  - )
Aerosoft's - Kastellorizo X - FSX (HKLM\...\Kastellorizo X - FSX) (Version: 1.00 - )
Aerosoft's - Seychelles X - FSX (HKLM\...\Seychelles X - FSX) (Version: 1.00 - Aerosoft)
Aerosoft's - VFR Germany 2 (HKLM\...\{3BB7B4D3-C534-4700-AA1B-B01A8EA5F27C}) (Version: 1.00 - Aerosoft)
Aerosoft's - VFR Germany 3 (HKLM\...\{61C6337D-EDF5-43F0-9E50-541A389070BD}) (Version: 1.00 - Aerosoft)
Aerosoft's - VFR Germany 4 (HKLM\...\{F7016342-C196-44B1-AAC5-D7BA4708473E}) (Version: 1.00 - Aerosoft)
Afterfall InSanity (HKLM\...\{CE9CAAA6-0431-433B-9FB5-23EE01669AF2}) (Version: 1.00.0000 - Nicolas Games S.A.)
Age of Empires II - the Conquerors WideScreen Patcher (HKLM\...\{BA2F3EBC-FE07-4AB5-B906-14DF2C74C523}) (Version: 1.0.40 - Boekabart)
Age of Empires II: HD Edition (HKLM\...\Steam App 221380) (Version:  - )
Age of Empires III - The Asian Dynasties (HKLM\...\InstallShield_{C43C1415-3DFC-4089-9A32-0BECF28A6046}) (Version: 1.00.0000 - Microsoft Game Studios)
Age of Empires III - The Asian Dynasties (Version: 1.00.0000 - Microsoft Game Studios) Hidden
Age of Empires III - The WarChiefs (HKLM\...\InstallShield_{1C08A24C-B168-407E-A826-68FAF5F20710}) (Version: 1.00.0000 - Microsoft Game Studios)
Age of Empires III - The WarChiefs (Version: 1.00.0000 - Microsoft Game Studios) Hidden
Age of Empires III (HKLM\...\InstallShield_{A8CF5C37-8EC5-4C33-BB4A-87F468B77D45}) (Version: 1.00.0000 - Microsoft Game Studios)
Age of Empires III (Version: 1.00.0000 - Microsoft Game Studios) Hidden
Age of Empires Online (HKLM\...\Steam App 105430) (Version:  - Microsoft)
Age of Mythology: Extended Edition (HKLM\...\QWdlb2ZNeXRob2xvZ3lFeHRlbmRlZEVkaXRpb24=_is1) (Version: 1 - )
AIDA64 Engineer v5.00 (HKLM\...\AIDA64 Engineer_is1) (Version: 5.00 - FinalWire Ltd.)
AIMP3 (HKLM\...\AIMP3) (Version: v3.60.1483, 27.02.2015 - AIMP DevTeam)
Airbus Series Vol.2 (FS X) (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Airbus Series Vol.2 (FS X)) (Version:  - )
Alan Wake (HKLM\...\Alan Wake_is1) (Version:  - )
Aliens Colonial Marines Limited Edition DLC Pack Plus Steam Vorbesteller-Bonus 1.0 (HKLM\...\Aliens Colonial Marines Limited Edition DLC Pack Plus Steam Vorbesteller-Bonus 1.0) (Version: 1.0 - .x.X.RIDDICK.X.x.)
Aliens vs Predator Classic 2000 (HKLM\...\1207665883_is1) (Version: 2.0.0.21 - GOG.com)
Aliens vs Predator D3D11 Benchmark V1.03 (HKLM\...\{CC72E6E8-CFFF-43B4-A9BE-C227C088EE95}) (Version: 1.03.0000 - Rebellion)
Aliens: Colonial Marines (HKLM\...\Aliens: Colonial Marines_is1) (Version:  - )
allSnap version 1.33.2 (HKLM\...\allSnap_is1) (Version: 1.33 - Ivan Heckman)
Alone In The Dark (HKLM\...\Alone In The Dark_is1) (Version:  - Atari)
America's Army 3 (HKLM\...\Steam App 13140) (Version:  - U.S. Army)
Amiga Forever (HKLM\...\{DCB8DF8D-6F0E-405B-B870-89709242F5C0}) (Version: 2012.2.0 - Cloanto)
Amnesia: The Dark Descent Demo  (HKLM\...\Steam App 57310) (Version:  - Frictional Games)
Anark Client 1.0 (HKLM\...\AnarkClient) (Version:  - )
AniMake (HKLM\...\AniMake) (Version:  - )
ANNO 1503 GOLD (HKLM\...\{DB833EF9-A198-49BE-970A-BD46F30BFBB4}) (Version: 1.05.00 - )
ANNO 1602 Königs-Edition (HKLM\...\{077A7810-A937-4465-AD08-ACED9807995F}) (Version: 1.00 - )
ANNO 2070 (HKLM\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft)
Anomos 0.9.5 (HKLM\...\Anomos) (Version: 0.9.5 - Anomos Liberty Enhancements)
ArCADia-GRAF 1.5 DE (HKLM\...\{887C98A0-1E31-4C8C-8B72-DA10A860AF71}) (Version: 1.5.6.16 - ArCADiasoft Chudzik sp. j.)
ArCon Professional +2011 (HKLM\...\{7C3C04ED-B746-4273-A0C8-997A8823CB36}) (Version: 15.0.0.0 - Eleco)
ArCon Professional +2011 (Version: 15.0.0.0 - Eleco) Hidden
Arma 3 Complete (HKLM\...\QXJtYTM=_is1) (Version: 1 - )
Assassin's Creed (R) III (HKLM\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.01 - Ubisoft)
Assassin's Creed Brotherhood (HKLM\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Attack Surface Analyzer (HKLM\...\{2710505A-D198-4906-8767-F869909D9FA6}) (Version: 5.3.0.0 - Microsoft Corporation)
Audacity 2.0.6 (HKLM\...\Audacity_is1) (Version: 2.0.6 - Audacity Team)
Auto Gordian Knot 2.55 (HKLM\...\AutoGK) (Version: 2.55 - len0x)
AviSynth 2.5 (HKLM\...\AviSynth) (Version:  - )
AVS Update Manager 1.0 (HKLM\...\AVS Update Manager_is1) (Version:  - Online Media Technologies Ltd.)
AVS Video Converter 7 (HKLM\...\AVS4YOU Video Converter 7_is1) (Version:  - Online Media Technologies Ltd.)
AVS4YOU Software Navigator 1.4 (HKLM\...\AVS4YOU Software Navigator_is1) (Version:  - Online Media Technologies Ltd.)
Baldur's Gate II (HKLM\...\Baldur's Gate II_is1) (Version:  - GOG.com)
Bandicam (HKLM\...\Bandicam) (Version: 2.1.2.740 - Bandisoft.com)
Bandisoft MPEG-1 Decoder (HKLM\...\BandiMPEG1) (Version:  - Bandisoft.com)
Baphomets Fluch - Der schlafende Drache (HKLM\...\Baphomets Fluch - Der schlafende Drache) (Version:  - )
Batman: Arkham City Digital Deluxe Edition (HKLM\...\{E8AC6BBD-9A99-404C-9638-F633312CD441}_is1) (Version: 1.0 - RAF)
Battle Realms Complete (HKLM\...\Battle Realms Complete_is1) (Version:  - GOG.com)
Battlefield 3™ (HKLM\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlefield Heroes (HKLM\...\{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}) (Version:  - EA Digital illusions)
Bejeweled® 3 (HKLM\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.)
Beneath a Steel Sky (HKLM\...\GOGPACKBENEATH_is1) (Version: 2.0.0.9 - GOG.com)
Bewerbungs-Experte 2011 (HKLM\...\Bewerbungs-Experte_is1) (Version: 3.0.0.0 - haude electronica verlag)
Binary Domain (HKLM\...\Binary Domain_is1) (Version:  - )
BioShock 2 (HKLM\...\{4A8B461A-9336-4CF9-98F4-14DD38E673F0}) (Version: 1.00.0000 - 2K Games)
BioShock Infinite (HKLM\...\BioShock Infinite_is1) (Version:  - )
Blade Runner (HKLM\...\Blade Runner) (Version: 1.05 -  Westwood Studios 1997)
Blender (HKLM\...\Blender) (Version: 2.69 - Blender Foundation)
Brutal Legend version 1 (HKLM\...\QnJ1dGFsIExlZ2VuZA==_is1) (Version: 1 - )
Bulletstorm (HKLM\...\GFWL_{45410935-3E72-472B-8C35-AB1000008200}) (Version: 1.0.0000.130 - EA)
Bulletstorm (Version: 1.0.0000.130 - EA) Hidden
Burnout(TM) Paradise The Ultimate Box (HKLM\...\{9A996B6A-846E-4A89-B9C4-17546B7BE49F}) (Version: 1.0.0.0 - Electronic Arts)
C&C Der Tiberiumkonflikt (HKLM\...\C&C Der Tiberiumkonflikt_is1) (Version:  - )
Cain & Abel 4.9.56 (HKLM\...\Cain & Abel 4.9.56) (Version:  - )
calibre (HKLM\...\{0CF3C0FA-02EA-4E15-9495-1C441C0377B3}) (Version: 2.18.0 - Kovid Goyal)
Call of Duty Black Ops GERMAN Uncut 1.00 (HKLM\...\Call of Duty Black Ops GERMAN Uncut 1.00) (Version:  - )
Call of Duty Modern Warfare 3 (c) Activision version 1 (HKLM\...\Call of Duty Modern Warfare 3 (c) Activision_is1) (Version: 1 - )
Call of Duty: Black Ops II v1.0 (HKLM\...\{26B8A445-02C6-4F87-AD2A-024BBFC99A06}_is1) (Version: 1.0 - RAF)
Cannon Fodder (HKLM\...\GOGPACKCANNONFODDER_is1) (Version: 2.0.0.3 - GOG.com)
Capitalism 2 (HKLM\...\GOGPACKCAPITALISM2_is1) (Version: 2.0.0.5 - GOG.com)
Castle of Illusion (HKLM\...\Q2FzdGxlb2ZJbGx1c2lvbg==_is1) (Version: 1 - )
Castlevania Lords of Shadow (HKLM\...\{F14EDCE5-B45D-4D77-A5B8-C7513E5C7BDA}) (Version: 6.0 - Black Box)
CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5143 - CDBurnerXP)
CDex - Open Source Digital Audio CD Extractor (HKLM\...\CDex) (Version: 1.72.1.2014 - Georgy Berdyshev)
Chaos auf Deponia Demo (HKLM\...\Deponia 2 Demo) (Version: 1.0 - Daedalic Entertainment)
Cheat Engine 6.2 (HKLM\...\Cheat Engine 6.2_is1) (Version:  - Dark Byte)
Cheatbook Database 2014 (HKLM\...\Cheatbook Database 2014) (Version:  - )
ClamWin Free Antivirus 0.98.4.1 (HKLM\...\ClamWin Free Antivirus_is1) (Version:  - alch)
ClassicPro© v2.01 (HKLM\...\ClassicPro) (Version: 2.01 - Skin Consortium)
ClearProg 1.6.1 Beta 8 (HKLM\...\ClearProg) (Version: 1.6.1 Beta 8 - Sven Hoffman)
CLICKBIOSII (HKLM\...\{EBCB111F-4907-4B28-BD03-F5BD901106D2}_is1) (Version: 1.0.123 - MSI)
Colin McRae Rally Remastered (HKLM\...\Colin McRae Rally Remastered_is1) (Version:  - )
Command & Conquer 3 (HKLM\...\{B0C30E93-D3D9-4F04-A2AC-54749B573275}) (Version: 1.00.0000 - Ihr Firmenname)
Command & Conquer Alarmstufe Rot 2 (HKLM\...\Red Alert 2) (Version:  - )
Command & Conquer Generals (HKLM\...\InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}) (Version: 0.50.0000 - Electronic Arts)
Command & Conquer Generals (Version: 0.50.0000 - Electronic Arts) Hidden
Command & Conquer Teil 3: Operation Tiberian Sun (HKLM\...\Tiberian Sun) (Version:  - )
Command & Conquer™ 3: Kanes Rache (HKLM\...\{CC2422C9-F7B5-4175-B295-5EC2283AA674}) (Version: 1.00.0000 - Ihr Firmenname)
Command & Conquer™ 4 Tiberian Twilight (HKLM\...\{82696435-8572-4D8B-A230-D1AA567D0F0F}) (Version: 1.0.0.0 - Electronic Arts)
Command & Conquer™ Alarmstufe Rot 3 (HKLM\...\{296D8550-CB06-48E4-9A8B-E5034FB64715}) (Version: 1.0.1.0 - Electronic Arts)
Command & Conquer™ Alarmstufe Rot 3 Der Aufstand (HKLM\...\{DDE59617-F59A-473B-BC4E-C2B81F6CD38D}) (Version: 1.0.1.0 - Electronic Arts)
Command && Conquer Alarmstufe Rot 2 - Yuris Rache (HKLM\...\Yuri's Revenge) (Version:  - )
Command and Conquer(TM) Generäle Die Stunde Null  (HKLM\...\InstallShield_{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}) (Version: 1.00.0000 - Electronic Arts)
Command and Conquer(TM) Generäle Die Stunde Null  (Version: 1.00.0000 - Electronic Arts) Hidden
Commando (HKLM\...\ComandoDeinstKey) (Version:  - )
Commandos 2: Men of Courage (HKLM\...\{F7963BA0-EE1C-11D4-9FA5-00A0C9E6A342}) (Version:  - )
Commandos 3 - Destination Berlin (HKLM\...\{C270BC04-1540-4673-960F-A546B2C860CD}) (Version:  - )
ConvertAll (HKLM\...\ConvertAll) (Version:  - )
Corel Graphics - Windows Shell Extension (HKLM\...\_{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}) (Version: 15.2.0.686 - Corel Corporation)
Corel Graphics - Windows Shell Extension (Version: 15.2.686 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Common (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Connect (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Custom Data (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - DE (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Draw (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - EN (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - ES (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Extra Content (HKLM\...\_{5A10CFDA-FA2B-453C-B561-AE864E62EAC8}) (Version:  - Corel Corporation)
CorelDRAW Essentials X5 - Extra Content (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Filters (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - FR (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - IPM (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - IT (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - PHOTO-PAINT (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Redist (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Setup Files (Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - WT (Version: 15.3 -  Corel Corporation) Hidden
CorelDRAW Essentials X5 (HKLM\...\_{EDBEBF07-F880-48FB-9AA5-0E8E71E02D83}) (Version: 15.2.0.686 - Corel Corporation)
CorelDRAW Essentials X5 (Version: 15.3 - Corel Corporation) Hidden
Counter-Strike Nexon: Zombies (HKLM\...\Steam App 273110) (Version:  - Nexon)
Counter-Strike: Global Offensive - SDK (HKLM\...\Steam App 745) (Version:  - )
Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version:  - Valve)
CPUID CPU-Z 1.72 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Crysis® 2 (HKLM\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.0.0.0 - Electronic Arts)
Crysis®3 (HKLM\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.1.0.0 - Electronic Arts)
CrystalDiskMark 3.0.3a (HKLM\...\CrystalDiskMark_is1) (Version: 3.0.3a - Crystal Dew World)
CyberLink PowerDVD 11 (HKLM\...\InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}) (Version: 11.0.1620.51 - CyberLink Corp.)
Dark Souls Prepare to Die Edition (HKLM\...\GFWL_{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.)
Dark Souls Prepare to Die Edition (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
Darksiders 1.1(CREATED BY XEONKING©) (HKLM\...\Darksiders_is1) (Version: 1.1 - )
Das Haus am See - Kinder der Stille Sammleredition 1.0.0.0 (HKLM\...\Das Haus am See - Kinder der Stille Sammleredition 1.0.0.0) (Version: 1.0.0.0 - Shadow - Time to play)
Das Telefonbuch Deutschland (HKLM\...\DasTelefonbuch Deutschland) (Version:  - TVG Telefonbuch- und Verzeichnisverlag GmbH & Co. KG)
Datennetzwerktechnik (HKLM\...\Datennetzwerktechnik) (Version:  - )
Dead Island Riptide (c) Deep Silver version 1 (HKLM\...\RGVhZCBJc2xhbmQgUmlwdGlkZSAoYykgRGVlcCBTaWx2ZXI=_is1) (Version: 1 - )
Dead Space (HKLM\...\{025A585C-0C66-413D-80D2-4C05CB699771}) (Version: 1.0.0.222 - Electronic Arts)
Dead Space™ 2 (HKLM\...\{96D06FDD-6AF4-4309-BC1B-1C9588B0575E}) (Version: 1.0.941.0 - Electronic Arts)
Delta Force (HKLM\...\Delta Force) (Version:  - )
Delta Force 2 (HKLM\...\Delta Force 2) (Version:  - )
Descent and Descent 2 (HKLM\...\Descent and Descent 2_is1) (Version:  - GOG.com)
DesignSpark Mechanical 2.0 (HKLM\...\{ADF11148-6555-FFFF-A320-274AF0C42282}) (Version: 10.0.0 - SpaceClaim Corporation)
Deus EX Human Revolution Version v1.1 (HKLM\...\{2DDC57D4-594D-4F30-8D81-27FDB2243644}_is1) (Version: v1.1 - ZKY)
D-Fend Reloaded 1.3.6 (deinstallieren) (HKLM\...\D-Fend Reloaded) (Version: 1.3.6 - Alexander Herzog)
Dia (nur entfernen) (HKLM\...\Dia) (Version:  - )
Die Siedler II - Die nächste Generation (HKLM\...\S2TNG) (Version:  - )
Die Sims™ 3 (HKLM\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.9.22 - Electronic Arts)
D-Info mit Rückwärtssuche Frühjahr 2012 (HKLM\...\{36F8E574-A5D0-425C-AF52-FFA2D4616ED6}) (Version: 1.00.0000 - telegate MEDIA AG)
DirSync  2.96 (HKLM\...\DirSync) (Version:  - Stephen Kalisch)
DiRT 3 (HKLM\...\GFWL_{434D0FA0-1558-4D8E-AC3D-BD1000008200}) (Version: 1.0.0000.130 - Codemasters)
DiRT 3 (Version: 1.0.0000.130 - Codemasters) Hidden
DLH98 v1.44 (HKLM\...\DLH98) (Version:  - )
Doc Scrubber v1.1 (HKLM\...\Doc Scrubber_is1) (Version: 1.1 - Javacool Software LLC)
Dolphin x86 (HKLM\...\Dolphin x86) (Version: 4.0.2 - Dolphin Development Team)
Doom 3: BFG Edition (HKLM\...\{2EBA122F-BB93-4FCF-ACC3-59374E7CF3C9}_is1) (Version: 1.0 - RAF)
Dr_Brain_GJ_Vol2 (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Dr_Brain_GJ_Vol2) (Version:  - )
Dracula Origin (HKLM\...\Dracula Origin_is1) (Version:  - )
Duke Nukem Forever DELUXE EDITION incl. dem DLC The Doctor Who Cloned Me 1.01 (HKLM\...\Duke Nukem Forever DELUXE EDITION incl. dem DLC The Doctor Who Cloned Me 1.01) (Version:  - )
DVD Identifier (HKLM\...\DVD Identifier_is1) (Version: 5.2.0 - Kris Schoofs)
DVD-lab PRO 2.0 (HKLM\...\DVD-lab PRO 2.0 deutsch_is1) (Version:  - )
Earthworm Jim 3D (HKLM\...\Earthworm Jim 3D_is1) (Version:  - GOG.com)
EAX Unified (HKLM\...\EAX Unified) (Version:  - )
Elektronik 2 V2.0 (HKLM\...\Elektronik 2 V2.0) (Version:  - )
eLicenser Control (HKLM\...\eLicenser Control) (Version:  - Steinberg Media Technologies GmbH)
EMET 5.1 (HKLM\...\{72E7AE20-5B12-4F27-AF5E-DA03E3C09466}) (Version: 5.1 - Microsoft Corporation)
Emsisoft HiJackFree 4.5 (HKLM\...\Emsisoft HiJackFree_is1) (Version: 4.5 - Emsisoft GmbH)
Enclave (HKLM\...\Steam App 253980) (Version:  - Topware)
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
EVEREST Ultimate Edition v5.30 (HKLM\...\EVEREST Ultimate Edition_is1) (Version: 5.30 - Lavalys, Inc.)
Everything 1.3.4.686 (x86) (HKLM\...\Everything) (Version:  - )
Far Cry 3 (HKLM\...\{3E7F5A51-7657-43D6-A9B3-C3A21473834B}_is1) (Version: 1.01 - RAF)
FEZ (HKLM\...\FEZ_is1) (Version:  - Trapdoor)
FIFA 14 Version 1.0 u1 (HKLM\...\FIFA 14_is1) (Version: 1.0 u1 - EA Games)
FileZilla Client 3.10.2 (HKLM\...\FileZilla Client) (Version: 3.10.2 - Tim Kosse)
Fischer Weltalmanach und Atlas 2012 (HKLM\...\InstallShield_{8B1B9DF1-DB57-4A69-8047-D64C0F46ADA7}) (Version: 1.00.0000 - USM)
Fischer Weltalmanach und Atlas 2012 (Version: 1.00.0000 - USM) Hidden
FixFoto 3.00 (HKLM\...\FixFoto_is1) (Version:  - Joachim Koopmann Software)
Flash Drive Tester v1.14 (HKLM\...\{272C8DEE-F54F-406C-9AA6-B4DE2985A47C}) (Version: 1.14 - Virtual Console)
Fraps (remove only) (HKLM\...\Fraps) (Version:  - )
FreeFileSync 6.13 (HKLM\...\FreeFileSync_is1) (Version: 6.13 - www.FreeFileSync.org)
FUEL (HKLM\...\{F51FF206-2273-4B3E-A90A-4752AE288C12}) (Version: 1.00.0000 - Codemasters)
Futuremark SystemInfo (HKLM\...\{A7E0E8D0-2E06-428A-8A8A-83BFF0B4DFE6}) (Version: 4.34.498.0 - Futuremark)
Gabelstapler 2014 1.0.2 (HKLM\...\{9B9000F2-DD0C-40AA-9ED6-6776B83894E1}_is1) (Version:  - UIG Entertainment)
Gabriel Knight - Sins of the Fathers Demo (HKLM\...\Steam App 318170) (Version:  - Phoenix Online Studios)
GALCOM Echo Squad SE Demo Docs (HKLM\...\GALCOM Echo Squad SE Demo Docs) (Version:  - 3000AD, Inc.)
Game Compatibility Database (HKLM\...\{0e82bf4c-b906-4635-a97e-6a9740686b33}.sdb) (Version:  - )
Gameforge Live 2.0.6 (HKLM\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.6 - Gameforge)
Gas Guzzlers Combat Carnage (HKLM\...\Gas Guzzlers Combat Carnage_is1) (Version:  - )
gbrainy 2.06 (HKLM\...\gbrainy) (Version: 2.06 - )
GCFScape 1.8.4 (HKLM\...\GCFScape_is1) (Version:  - Ryan Gregg)
Gears of War (HKLM\...\InstallShield_{1170D24F-42B7-40CF-AA1B-6395CE562354}) (Version: 1.00.0000 - Microsoft Game Studios)
Gears of War (Version: 1.00.0000 - Microsoft Game Studios) Hidden
Geeks3D PhysX FluidMark v1.5.2 (HKLM\...\{0B7C79A5-5CB2-4ABD-A9C1-92A6213CE8DD}_is1) (Version:  - Geeks3D.com)
Geeks3D.com FurMark 1.10.1 (HKLM\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version:  - Geeks3D.com)
Gehirnjogging - Generations (HKLM\...\CD_Gehirnjogging_Generations_DE) (Version:  - )
Gehirnjogging 4 (HKLM\...\Gehirnjogging 4) (Version: 1.0 - SBT)
Gemeinsam genutzte Internet-Komponenten von Westwood (HKLM\...\WOLAPI) (Version:  - )
GetRight (HKLM\...\GetRight_is1) (Version:  - Headlight Software, Inc.)
Gods Will Be Watching (HKLM\...\1207664883_is1) (Version: 2.0.0.1 - GOG.com)
GoldWave v5.66 (HKLM\...\GoldWave v5.66) (Version:  - )
Goodbye Deponia Demo (HKLM\...\Steam App 262880) (Version:  - Daedalic Entertainment)
Google Earth Pro (HKLM\...\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
GPS-Track-Analyse.NET 6.0 (HKLM\...\GPS-Track-Analyse.NET 6.0_is1) (Version:  - )
Grand Theft Auto IV (HKLM\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (Version: 1.0.0011.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV (Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
GRID Autosport (HKLM\...\GRID Autosport_is1) (Version: GRID Autosport - )
GSAK 8.4.0.0 (HKLM\...\GSAK_is1) (Version:  - CWE computer services)
GTA IV Vehicle Mod Installer v1.2 (HKLM\...\GTA IV Vehicle Mod Installer v1.2_is1) (Version:  - MobileD2)
Gunpoint Demo (HKLM\...\Steam App 240570) (Version:  - )
Half-Life Singleplayer Edition (HKLM\...\{D2FEF059-3942-4E50-B825-4E208DBC63F2}_is1) (Version: 1.1.2010 - Valve)
HashTab 5.2.0.14 (HKLM\...\HashTab) (Version: 5.2.0.14 - Implbits Software)
Haunted Past - Im Reich der Geister 1.00 (HKLM\...\Haunted Past - Im Reich der Geister 1.00) (Version:  - )
HD Tune Pro 5.00 (HKLM\...\HD Tune Pro_is1) (Version:  - EFD Software)
Heaven Benchmark version 4.0 (HKLM\...\Unigine Heaven Benchmark (Basic Edition)_is1) (Version: 4.0 - Unigine Corp.)
Heaven DX11 Benchmark version 3.0 (HKLM\...\Unigine Heaven DX11 Benchmark (Basic Edition)_is1) (Version: 3.0 - Unigine Corp.)
HijackThis 2.0.2 (HKLM\...\HijackThis) (Version: 2.0.2 - TrendMicro)
Hitman Absolution (HKLM\...\Hitman Absolution_is1) (Version:  - )
Homebrew - Vehicle Sandbox Demo (HKLM\...\Steam App 327770) (Version:  - Copybugpaste)
Homefront (HKLM\...\Homefront_is1) (Version:  - )
HWiNFO32 Version 4.42 (HKLM\...\HWiNFO32_is1) (Version: 4.42 - Martin Malík - REALiX)
HyperSnap 6 (HKLM\...\HyperSnap 6) (Version: 6.70.02 - Hyperionics Technology LLC)
IconPackager (HKLM\...\IconPackager) (Version: 5.10.032 - Stardock Corporation)
IconPackager (Version: 5.10.032 - Stardock Corporation) Hidden
ImgBurn (HKLM\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
Incredipede (HKLM\...\GOGPACKINCREDIPEDE_is1) (Version: 2.0.0.4 - GOG.com)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.8.251 - Intel Corporation)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.35 - Irfan Skiljan)
IsoBuster 3.5 (HKLM\...\IsoBuster_is1) (Version: 3.5 - Smart Projects)
IT-Sicherheit (HKLM\...\IT-Sicherheit) (Version:  - )
Jagged Alliance (HKLM\...\Jagged Alliance_is1) (Version:  - GOG.com)
Jagged Alliance 2 (HKLM\...\Jagged Alliance 2_is1) (Version:  - GOG.com)
Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Java 8 Update 40 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
JonDo (HKLM\...\JonDoUninstall) (Version:  - )
jStrip 3.3 (HKLM\...\jStrip_is1) (Version: 3.3 - David Crowell)
Kalenderchen 5 (HKLM\...\{11464943-4682-4F6B-A96D-D4E8C26DD111}_is1) (Version:  - Daniel Manger)
KaloMa 4.92 (HKLM\...\KaloMa_is1) (Version:  - Frank Böpple)
KeePass Password Safe 2.27 (HKLM\...\KeePassPasswordSafe2_is1) (Version: 2.27 - Dominik Reichl)
Kingdoms of Amalur: Reckoning (HKLM\...\{6A9D1594-7791-48f5-9CAA-DE9BCB968320}) (Version: 1.0.0.0 - Electronic Arts)
K-Lite Codec Pack 11.0.0 Full (HKLM\...\KLiteCodecPack_is1) (Version: 11.0.0 - )
K-Meleon 74.0 (x86 en-US) (HKLM\...\K-Meleon 74.0 (x86 en-US)) (Version: 74.0 - kmeleonbrowser.org)
Knights and Merchants (HKLM\...\Steam App 253900) (Version:  - Topware Interactive)
Kolor Autopano Giga 3.6 (HKLM\...\AutopanoGiga3.6) (Version: V3.6.3 - Kolor)
Lara Croft and the Guardian of Light (HKLM\...\Lara Croft and the Guardian of Light_is1) (Version:  - )
LauschAngriff (HKLM\...\LauschAngriff) (Version:  - )
LEGO - The Hobbit (HKLM\...\TEVHT1RoZUhvYmJpdA==_is1) (Version: 1 - )
LEGO Batman 3 - Beyond Gotham (HKLM\...\TEVHT0JhdG1hbjNCZXlvbmRHb3RoYW0=_is1) (Version: 1 - )
LEGO Digital Designer (HKLM\...\New LEGO Digital Designer) (Version:  - LEGO A/S)
LEGO MARVEL Super Heroes (HKLM\...\LEGO MARVEL Super Heroes_is1) (Version:  - Warner Bros. Games)
LEGO® Batman™ (HKLM\...\InstallShield_{398AB469-77FC-4935-820B-D419388C0A6A}) (Version: 1.00.0000 - Warner Bros. Interactive Entertainment)
LEGO® Batman™ (Version: 1.00.0000 - Warner Bros. Interactive Entertainment) Hidden
LEGO® Der Herr der Ringe™ (HKLM\...\{C6F20FA7-342A-47A9-A3C8-EB36CABE6419}) (Version: 1.0.0.0 - Warner Bros. Interactive Entertainment)
LEGO® Pirates of the Caribbean Das Videospiel (HKLM\...\{64958DA4-79D3-43FD-AF06-720DAD044F9E}) (Version: 1.0.0.0 - Disney Interactive Studios)
Leistungselektronik (HKLM\...\Leistungselektronik) (Version:  - )
Life Goes On Demo (HKLM\...\Steam App 246380) (Version:  - )
Lightworks (HKLM\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 12.0.2.0 - Lightworks)
Logitech Gaming Software 5.10 (HKLM\...\{60D32CDC-E3BE-4578-BA10-29322307CDDC}) (Version: 5.10.127 - Logitech)
LOST PLANET 2 (HKLM\...\{737369DC-08E8-4787-A78C-F86943247BDF}) (Version: 1.0.0.129 - CAPCOM CO., LTD.)
MadOnion.com/3DMark2000 (HKLM\...\MadOnion.com/3DMark2000) (Version:  - )
MadOnion.com/3DMark2001 SE (HKLM\...\{91B323B5-A79C-4D23-BD6D-046C565F9BCF}) (Version:  - )
Magic Games II (HKLM\...\{AB38070F-5479-4F76-8419-80A758B7B16B}) (Version: 1.0.0 - magicn)
Magic The Gathering - Duels of the Planeswalkers (HKLM\...\Magic The Gathering - Duels of the Planeswalkers_is1) (Version:  - )
Magical Jelly Bean KeyFinder (HKLM\...\KeyFinder_is1) (Version: 2.0.9.8 - Magical Jelly Bean)
MahJong Suite 2011 v8.2 (HKLM\...\MahJong Suite_is1) (Version:  - TreeCardGames)
Majesty 2: The Fantasy Kingdom Sim (HKLM\...\{CDCA3C32-FCE7-40E8-8CB5-7B0E87ADDFC9}_is1) (Version: 1.0.0.0 - Paradox Interactive)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Mandelbulber (HKLM\...\35A39AB0-5E9F-4B70-98DA-4B8158C89C4B) (Version: 1.21-1 - )
Maniac Mansion Deluxe (HKLM\...\Maniac Mansion Deluxe) (Version:  - )
Medal of Honor™ Warfighter Deutsch Patch 1.00 (HKLM\...\Medal of Honor™ Warfighter Deutsch Patch 1.00) (Version:  - )
MediaCoder 0.8.30.5622 (HKLM\...\MediaCoder) (Version: 0.8.30.5622 - Mediatronic)
Memoria Demo (HKLM\...\Steam App 250940) (Version:  - Daedalic Entertainment)
Metro Last Light Update 12 (v1.0.0.14) Plus limited First Edition DLCs Plus Chronicles Pack DLC v1.0.0.14 (HKLM\...\Metro Last Light Update 12 (v1.0.0.14) Plus limited First Edition DLCs Plus Chronicles Pack DLC v1.0.0.14) (Version:  - )
Metro: Last Light (c) Deep Silver version 1 (HKLM\...\TWV0cm9MYXN0TGlnaHQ=_is1) (Version: 1 - )
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Age of Empires Gold (HKLM\...\Age of Empires Gold 1.0) (Version:  - )
Microsoft Age of Empires II (HKLM\...\Age of Empires 2.0) (Version:  - )
Microsoft Age of Empires II: The Conquerors Expansion (HKLM\...\Age of Empires II: The Conquerors Expansion 1.0) (Version:  - )
Microsoft Baseline Security Analyzer 2.3 (HKLM\...\{C3013E88-B772-4446-A0AE-A7F37180B9F1}) (Version: 2.3.2208 - Microsoft Corporation)
Microsoft Flight Simulator X Service Pack 2 (HKLM\...\{E7CC4B85-DC2F-463F-8FEB-E7398E25C19A}) (Version: 10.0.61472.0 - Microsoft Game Studios)
Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Image Composite Editor (HKLM\...\{3D599ADA-65D9-4B51-898F-CE718DEC5DBB}) (Version: 1.4.4 - Microsoft Corporation)
Microsoft Keyboard Layout Creator 1.4 (HKLM\...\{99E66BC9-E4B6-485F-ABFC-31EFCE36DFDF}) (Version: 1.4.6000 - Microsoft Corp.)
Microsoft LifeCam (HKLM\...\{BD71B413-9FEE-49BB-A6D1-2C0BFB99BDFE}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{485DE620-A598-4481-ACDC-61734504DB74}) (Version: 11.0.2318.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{09298F26-A95C-31E2-9D95-2C60F586F075}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Windows Performance Toolkit (HKLM\...\{E7F9E526-2324-437B-A609-E8C5309465CB}) (Version: 4.8.0 - Microsoft Corporation)
Microsoft Windows SDK for Windows 7 (7.1) (HKLM\...\SDKSetup_7.1.7600.0.30514) (Version: 7.1.7600.0.30514 - Microsoft Corporation)
Microsoft WorldWide Telescope (HKLM\...\{7785F029-FBFF-4572-8E1C-596D8A28B548}) (Version: 5.1.09 - Microsoft Research)
Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{AC4C38FD-A54C-4CA5-92EE-D983CD81293E}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Midori 0.5.9 (HKLM\...\Midori) (Version: 0.5.9 - Christian Dywan)
Mind Path to Thalamus (HKLM\...\Mind Path to Thalamus_is1) (Version:  - )
Minecraft1.7.9 (HKLM\...\Minecraft1.7.9) (Version:  - )
MiniTool Partition Wizard Free 9.0 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
mirkes.de Tiny Hexer (HKLM\...\{CC399A03-4695-432E-AE6E-BB450DDE5248}_is1) (Version: 1.8 - markus stephany)
Mirror's Edge™ (HKLM\...\{AEDBD563-24BB-4EE3-8366-A654DAC2D988}) (Version: 1.0.0.0 - Electronic Arts)
Monitor Calibration Wizard 1.0 (HKLM\...\Monitor Calibration Wizard) (Version:  - )
Monkey Island™ Special Edition Collection (HKLM\...\MISEC) (Version: 1.0.0.0 - LucasArts)
MonochromiX 1.39 (HKLM\...\MonochromiX_is1) (Version:  - Joachim Koopmann Software)
Monopoly (HKLM\...\{D7E7EC5E-4349-4E40-B37C-4342188B86EC}) (Version:  - )
Moo0 System Monitor 1.76 (HKLM\...\Moo0 SystemMonitor) (Version:  - )
Moorhuhn Remake (HKLM\...\{52210D57-0B1F-4681-90DD-8659DF4BCC40}) (Version: 1.00.0000 - )
MozBackup 1.5.1 (HKLM\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 36.0.4 (x86 de) (HKLM\...\Mozilla Firefox 36.0.4 (x86 de)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MPU (HKLM\...\{18F6D695-66FF-411C-9347-55D1140A7D7B}) (Version: 1.1.8 - Hergarten Media)
MSI Afterburner 4.0.0 (HKLM\...\Afterburner) (Version: 4.0.0 - MSI Co., LTD)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser und SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
MyFFVideoConverter (HKLM\...\MyFFVideoConverter) (Version: 1.0.0.0 - Pergel.hu)
NASA World Wind 1.4 (HKLM\...\NASA World Wind 1.4) (Version:  - )
NASAEyes (HKLM\...\{3E9B108D-9985-4043-B0B0-29F29221C9A6}) (Version: 1.0.0.0 - JPL/NASA-Caltech)
Native Instruments Traktor DJ Studio 3 (HKLM\...\Native Instruments Traktor DJ Studio 3) (Version:  - )
Need for Speed™ ProStreet (HKLM\...\{2E1A71D5-7897-4F3F-B0E3-B412C86A646D}) (Version: 1.0.1.0 - Electronic Arts)
Need for Speed™ Rivals (HKLM\...\{E0A32336-AA27-4053-99B2-C3380B7B95AC}) (Version: 1.3.0.0 - Electronic Arts)
Need For Speed™ World (HKLM\...\{3AF1B16A-7DC9-4C80-BAEC-70B088A7C5B8}) (Version: 1.0.0.0 - Electronic Arts)
Nemeth Designs Bell UH-1 Huey for Microsoft Flight Simulator X (HKLM\...\Nemeth Designs Bell UH-1 Huey for Microsoft Flight Simulator X) (Version:  - )
NetLimiter 3 (HKLM\...\{913923AB-3AAB-4870-8910-627C4CD82789}) (Version: 3.0.0.11 - Locktime Software s.r.o.)
NetSetMan 3.7.3 (HKLM\...\NetSetMan_is1) (Version: 3.7.3 - Ilja Herlein)
NetSpeedMonitor 2.5.4.0 x86 (HKLM\...\{86501894-E722-4385-A792-B7C2F28FAE7B}) (Version: 2.5.4.0 - Florian Gilles)
NetTools 5.0 (HKLM\...\NetTools_is1) (Version: 5.0 - Mohammad Ahmadi Bidakhvidi)
NexusFont 2.5 (ver 2.5.8.1582) (HKLM\...\{EFEDD205-43FE-4208-B682-0937E803E19E}_is1) (Version:  - xiles)
NNScript (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\NoNameScript) (Version: 4.22 - ESNation)
Notepad++ (HKLM\...\Notepad++) (Version: 6.5.3 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 347.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 347.09 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.52 - NVIDIA Corporation)
NVIDIA Alien vs. Triangles demo (HKLM\...\Alien vs. Triangles) (Version: 1.0 - NVIDIA Corporation)
NVIDIA FaceWorks: Real-time Performance Capture Demo (HKLM\...\FaceWorks) (Version: 1.0 - NVIDIA Corporation)
NVIDIA Grafiktreiber 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.52 - NVIDIA Corporation)
NVIDIA Hair Demo (HKLM\...\{BF2D55FB-975E-4B59-9C10-439A975701FF}) (Version: 1.00 - )
NVIDIA HD-Audiotreiber 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
NVIDIA Screen Saver 1.2 (HKLM\...\NVIDIA Screen Saver_is1) (Version:  - )
NVIDIA Supersonic Sled demo (HKLM\...\Supersonic Sled) (Version:  - )
O&O Defrag Professional (HKLM\...\{24CD85A3-6562-4C24-8257-27826C7CF7FE}) (Version: 15.8.813 - O&O Software GmbH)
O&O SafeErase Professional (HKLM\...\{4649998A-0D48-45C2-AF5B-FBD5ECF536ED}) (Version: 5.1.636 - O&O Software GmbH)
O&O UnErase (HKLM\...\{37F6190F-8A86-4B19-86A3-5A59BEA62823}) (Version: 6.0.1899 - O&O Software GmbH)
OMSI - Der Omnibussimulator (HKLM\...\{9AE850A4-B89D-4875-A159-B1B64D717EFB}) (Version: 1.06 - aerosoft)
OpenAL (HKLM\...\OpenAL) (Version:  - )
OpenVPN 2.3.4-I603  (HKLM\...\OpenVPN) (Version: 2.3.4-I603 - )
Opera 12.17 (HKLM\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
Oracle VM VirtualBox 4.3.26 (HKLM\...\{26B8608D-6C29-4171-9751-67621C834AA3}) (Version: 4.3.26 - Oracle Corporation)
Orcs Must Die 2 - Language Addon (HKLM\...\Orcs Must Die 2_is1) (Version:  - )
Orcs Must Die! Unchained (HKLM\...\{8EBA33AF-48E0-4207-A4EE-96029415AD76}_is1) (Version:  - Gameforge 4D GmbH)
Origin (HKLM\...\Origin) (Version: 9.1.11.2678 - Electronic Arts, Inc.)
PA38 Tomahawk FSX/P3D (HKLM\...\PA38 Tomahawk FSX/P3D) (Version: 1.00.00.00 - ALABEO)
PAC-MAN Championship Edition DX+ Demo (HKLM\...\Steam App 247260) (Version:  - Mine Loader Software Co., Ltd.)
Painkiller Hell and Damnation (HKLM\...\Painkiller Hell and Damnation_is1) (Version:  - )
Paragon ExtFS for Windows (HKLM\...\ParagonExtFS) (Version:  - )
Paragon Hard Disk Manager™ 14 Suite (HKLM\...\{29258311-EA49-11DE-967C-005056C00008}) (Version: 90.00.0003 - Paragon Software)
Path of Exile (HKLM\...\Steam App 238960) (Version:  - Grinding Gear Games)
Pazera Free Audio Extractor 1.4 (HKLM\...\{6899C238-3E4A-4A04-B251-A0C9EDC7EDBC}_is1) (Version: 1.4 - Pazera Jacek)
PC Tune-Up (Version: 2.2.0.1 - ZoneAlarm) Hidden
PCMark 7 (HKLM\...\{75C3C9C0-6CE6-42FA-A0E9-658E8F539124}) (Version: 1.4.0 - Futuremark)
PCSX2 - Playstation 2 Emulator (HKLM\...\pcsx2-r5875) (Version:  - )
PDF Settings CS5 (Version: 10.0 - Adobe Systems Incorporated) Hidden
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.311.0 - Tracker Software Products Ltd)
PeerBlock 1.2 (r693) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.2.0.693 - PeerBlock, LLC)
PeerGuardian 2.0 (HKLM\...\PeerGuardian_is1) (Version: 2.0.6.4 - Methlabs Productions)
Pluto Client (HKLM\...\{F8584160-CC6E-11d5-954F-5254AB1A4DB7}) (Version:  - )
Portal 2 Version 1.0 u23 (HKLM\...\Portal 2_is1) (Version: 1.0 u23 - Valve)
Portrait Professional Studio 9.8 (HKLM\...\PortraitProfessionalStudio9_is1) (Version: 9.8 - Anthropics Technology Ltd.)
Pro Evolution Soccer 2014 - World Challenge (HKLM\...\Pro Evolution Soccer 2014 - World Challenge_is1) (Version:  - )
Pro Evolution Soccer 2015 Demo (HKLM\...\Steam App 321280) (Version:  - KONAMI Digital Entertainment)
Prototype 2 (HKLM\...\Prototype 2_is1) (Version:  - )
Prototype(TM) (HKLM\...\InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}) (Version: 1.0 - Activision)
Prototype(TM) (Version: 1.0 - Activision) Hidden
Puppet Show 5 - Ungewisses Schicksal Sammleredition (HKLM\...\Puppet Show 5 - Ungewisses Schicksal Sammleredition 1.0) (Version: 1.0 - Dok)
Quake (HKLM\...\Quake_is1) (Version:  - )
Quake 4 1.4.2 (HKLM\...\Quake 4 1.4.2) (Version:  - )
Quake III Arena (HKLM\...\Quake III Arena) (Version:  - )
Quest for Infamy  (HKLM\...\Quest for Infamy) (Version:  - Infamous Quests)
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Rage Complete Edition MULTi-9 1.3 (HKLM\...\Rage Complete Edition MULTi-9 1.3) (Version:  - )
Railworks 3 Train Simulator 2012 Deluxe (HKLM\...\Railworks 3 Train Simulator 2012 Deluxe_is1) (Version:  - )
RamDisk Plus 11.6 (HKLM\...\{D96E4F17-2635-4CBD-9308-F99228929C41}) (Version: 11.6.795 - SuperSpeed LLC)
Rapture3D 2.4.8 Game (HKLM\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
Ravensburger Puzzle 2 (HKLM\...\Ravensburger Puzzle 2) (Version: 1.0 - Ravensburger Digital)
Rayman 2 - The Great Escape (HKLM\...\GOGPACKRAYMAN2_is1) (Version: 2.0.0.38 - GOG.com)
Rayman Forever (HKLM\...\GOGPACKRAYMANFOREVER_is1) (Version: 2.0.0.15 - GOG.com)
Rayman Legends Demo (HKLM\...\Steam App 243340) (Version:  - )
Razer Imperator (HKLM\...\{C05905B9-775A-4894-A4DF-B57C15250958}) (Version: 2.02.00 - Razer USA Ltd.)
Razer Synapse (HKLM\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.19.24565 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7399 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver and Utility (HKLM\...\{0DF70CB6-553A-4C57-8E6D-87635EECFB78}) (Version: 1.00.0145 - ALFA NETWORK Inc..)
REAPER (HKLM\...\REAPER) (Version:  - )
Redneck Rampage Collection (HKLM\...\Redneck Rampage Collection_is1) (Version:  - GOG.com)
Renegade X Black Dawn (HKLM\...\UDK-5848cd63-de6d-4847-9e8d-6abc3bcd6aef) (Version:  - Epic Games, Inc.)
RESIDENT EVIL 5 (HKLM\...\{AC08BBA0-96B9-431A-A7D0-D8598E493775}) (Version: 1.0.0.129 - CAPCOM CO., LTD.)
Resident Evil 6 Benchmark (HKLM\...\{0343CD8E-625A-47FF-BC7E-92BCDF2E5929}) (Version: 1.00.0000 - CAPCOM CO., LTD.)
Resident Evil 6 version 1 (HKLM\...\UmVzaWRlbnQgRXZpbCA2_is1) (Version: 1 - )
Resident Evil Revelations (HKLM\...\Resident Evil Revelations_is1) (Version:  - Capcom)
Resident Evil: Operation Raccoon City (HKLM\...\{43430FA1-12BB-4D88-862E-4F1000008400}) (Version: 1.0.0.0 - CAPCOM U.S.A., INC)
RetroShare (HKLM\...\RetroShare) (Version:  - )
REX 4 - Texture Direct (HKLM\...\{CACCC25C-70B5-4FD1-AF01-10D11B87DED8}) (Version: 4.0.2013.1215 - REX Game Studios, LLC.)
rFactor Demo (HKLM\...\Steam App 353320) (Version:  - Image Space Incorporated)
Rise of the Triad (HKLM\...\GOGPACKROTT2013_is1) (Version: 2.1.0.6 - GOG.com)
RivaTuner Statistics Server 6.2.0 (HKLM\...\RTSS) (Version: 6.2.0 - Unwinder)
RMPrepUSB (HKLM\...\RMPrepUSB) (Version:  - )
RollerCoaster Tycoon 2 Triple Thrill Pack (German) (HKLM\...\GOGPACKRCT2_is1) (Version: 2.0.0.6 - GOG.com)
RollerCoaster Tycoon 3 (HKLM\...\RollerCoaster Tycoon 3_is1) (Version:  - Atari)
RollerCoaster Tycoon Deluxe (German) (HKLM\...\GOGPACKRTC_is1) (Version: 2.1.0.18 - GOG.com)
S.T.A.L.K.E.R. - Call Of Pripyat [v1.6.01] (HKLM\...\{406FB8A4-F539-48A9-809C-F94706F9C9F6}_is1) (Version: 1.6.01 - bitComposer Games)
S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0006] (HKLM\...\S.T.A.L.K.E.R. - Shadow of Chernobyl_is1) (Version: 1.0006 - THQ)
Saints Row The Third (HKLM\...\Saints Row The Third_is1) (Version:  - )
Sang-Froid - Tales of Werewolves Demo (HKLM\...\Steam App 261240) (Version:  - Artifice Studio)
SCANIA Truck Driving Simulator 1.0.0 (HKLM\...\SCANIA Truck Driving Simulator) (Version: 1.0.0 - SCS Software)
Schlag den Raab - Das 3. Spiel (HKLM\...\SDR3) (Version: 1.0 - Sproing Interactive GmbH)
Schlagwortsuche 1.14 (HKLM\...\Schlagwortsuche_is1) (Version:  - Joachim Koopmann Software)
SDFormatter (HKLM\...\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SILENT HILL 4 (HKLM\...\{00BD992A-D4C7-447D-8AA1-60B5759EA30D}) (Version: 1.00.000 - )
SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts)
Singularity(TM) (HKLM\...\InstallShield_{3FAD68D9-1FA1-4871-9ADF-9151D969E943}) (Version: 1.00.0000 - Activision)
SiSoftware Sandra Lite 2014.SP2 (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1) (Version: 20.28.2014.5 - SiSoftware)
SMAC 2.7 (HKLM\...\SMAC 2.7) (Version:  - )
Sniper - Ghost Warrior (HKLM\...\Sniper - Ghost Warrior_is1) (Version:  - )
Sniper Elite V2 (HKLM\...\Steam App 63380) (Version:  - Rebellion)
Sniper: Ghost Warrior - Map Pack (HKLM\...\Sniper - Ghost Warrior - Map Pack/EN-English_is1) (Version:  - City Interactive)
SniperEliteV2 Benchmark 1.05 (HKLM\...\{2BA01EC9-E9F3-453C-AF5B-51E87FD4A0F1}) (Version: 1.05.0000 - Rebellion)
Software Director (HKLM\...\Cloanto Software Director) (Version: 3.8.8.0 - Cloanto Corporation)
Sonic the Hedgehog 4 - Episode II (c) SEGA version 1 (HKLM\...\Sonic the Hedgehog 4 - Episode II (c) SEGA_is1) (Version: 1 - )
SpeedFan (remove only) (HKLM\...\SpeedFan) (Version:  - )
Spintires (HKLM\...\Spintires_is1) (Version:  - )
Splinter Cell: Blacklist (HKLM\...\{28B718F4-73E8-4541-909C-0BA05F7402C2}_is1) (Version: 1.01 - Ubisoft)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Spyware Terminator 2012 (HKLM\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.80 - Crawler.com)
SRWare Iron Version SRWare Iron 41.2200.0 (HKLM\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: SRWare Iron 41.2200.0 - SRWare)
Star Wars: The Old Republic (HKLM\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Starbound with Update 9.5 (HKLM\...\Starbound with Update 9.5) (Version: with Update 9.5 - by Unterbilker)
Starcraft (HKLM\...\Starcraft) (Version:  - )
StarCraft™ II Wings of Liberty (HKLM\...\{7586F650-5D7F-471a-941E-FEF33E580524}_is1) (Version: 1.3.6 - QfG)
StarWind V2V Image Converter V5.6 (build 2011-05-10) (HKLM\...\StarWind Converter_is1) (Version:  - StarWind Software)
StaudSoft's Synthetic World Demo (HKLM\...\Steam App 344920) (Version:  - StaudSoft)
Stone Giant 1.0 (HKLM\...\{1FC46D21-F4A4-42DF-B9A4-27F8A702EBC5}_is1) (Version:  - BitSquid & Fatshark)
Streamripper (Remove only) (HKLM\...\Streamripper) (Version:  - )
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Syndicate (HKLM\...\Syndicate_is1) (Version:  - )
System Shock2 Demo (HKLM\...\SShockDeinstallKey) (Version:  - )
TAP-Windows 9.21.0 (HKLM\...\TAP-Windows) (Version: 9.21.0 - )
Technitium MAC Address Changer v6.0.5 (HKLM\...\TMACv6.0) (Version: 6.0.5 - Technitium)
Teenagent (HKLM\...\GOGPACKTEENAGENT_is1) (Version: 2.0.0.12 - GOG.com)
Telefonbuch für Deutschland (HKLM\...\Telefonbuch für Deutschland) (Version:  - )
Test Drive Unlimited 2 (HKLM\...\Test Drive Unlimited 2_is1) (Version:  - Atari)
Test Drive: Ferrari Racing Legends (HKLM\...\Test Drive: Ferrari Racing Legends_is1) (Version:  - )
The Dude (HKLM\...\Dude) (Version:  - )
The LEGO Movie - Videogame (HKLM\...\The LEGO Movie - Videogame_is1) (Version:  - Warner Bros. Interactive Entertainment)
The Lost Watch II NV 3D Screensaver 1.0 (HKLM\...\The Lost Watch II NV 3D Screensaver_is1) (Version: 1.0 - 3Planesoft)
The Night of the Rabbit Demo (HKLM\...\Steam App 241890) (Version:  - Daedalic Entertainment)
The Witcher 2 - Assassins of Kings Enhanced Edition (HKLM\...\The Witcher 2 - Assassins of Kings Enhanced Edition_is1) (Version:  - GOG.com)
Theme Hospital (HKLM\...\Theme Hospital_is1) (Version:  - GOG.com)
Tom Clancy's Rainbow Six Vegas 2 (HKLM\...\{FD416706-875C-4B0B-A23A-9E740DAE029E}) (Version: 1.00 - Ubisoft)
Tor (remove only) (HKLM\...\Tor) (Version:  - )
Tormentum - Dark Sorrow Demo (HKLM\...\Steam App 347680) (Version:  - OhNoo Studio)
Trend Micro RUBotted 2.0 Beta (HKLM\...\{54D4EAF5-4C80-4878-B4AC-5AE454A02E3C}_is1) (Version: 2.0.0.1034 - Trend Micro, Inc.)
Trials Evolution Gold Edition (HKLM\...\InstallShield_{07D857B8-C956-401D-BC8F-EDA8459AF037}) (Version: 1.0.0.1 - Ubisoft)
Trials Evolution Gold Edition (Version: 1.0.0.1 - Ubisoft) Hidden
Tribler (HKLM\...\Tribler) (Version: 6.4.3 - The Tribler Team)
Ubisoft Game Launcher (HKLM\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Ultra Defragmenter (HKLM\...\UltraDefrag) (Version: 6.0.4 - UltraDefrag Development Team)
Unigine Valley Benchmark version 1.0 (HKLM\...\Unigine Valley Benchmark_is1) (Version: 1.0 - Unigine Corp.)
Universal Adb Driver (HKLM\...\{D9C4202E-6D51-4B06-A8F1-22316E654BCA}) (Version: 1.0.0 - ClockworkMod)
Universal Extractor 1.6.1 (HKLM\...\Universal Extractor_is1) (Version: 1.6.1 - Jared Breland)
Unlocker 1.9.1 (HKLM\...\Unlocker) (Version: 1.9.1 - Cedrick Collomb)
Unreal Gold (HKLM\...\Unreal Gold_is1) (Version:  - GOG.com)
Unreal Tournament  – Game of the Year Edition (HKLM\...\Unreal Tournament  – Game of the Year Edition_is1) (Version:  - GOG.com)
Unreal Tournament 2003 (HKLM\...\UT2003) (Version:  - )
Unreal Tournament 2004 (HKLM\...\Unreal Tournament 2004_is1) (Version:  - GOG.com)
Unreal Tournament 3 Black Edition (HKLM\...\Unreal Tournament 3 Black Edition_is1) (Version:  - )
Uplay (HKLM\...\Uplay) (Version: 4.9 - Ubisoft)
Uplink (HKLM\...\Uplink_is1) (Version:  - GOG.com)
VC 9.0 Runtime (Version: 1.0.0 - Check Point Software Technologies Ltd) Hidden
Virtual CD v10 (HKLM\...\{10C51313-A308-4B40-90E3-B368D5882660}) (Version: 10.10.14 - H+H Software GmbH)
Vistumbler (HKLM\...\Vistumbler) (Version: v10 - Vistumbler.net)
Visual Basic 5.0 (HKLM\...\ST5UNST #1) (Version:  - )
VLC media player (HKLM\...\VLC media player) (Version: 2.2.0 - VideoLAN)
VMware Workstation (HKLM\...\VMware_Workstation) (Version: 10.0.3 - VMware, Inc)
VMware Workstation (Version: 10.0.3 - VMware, Inc.) Hidden
VobSub v2.23 (Remove Only) (HKLM\...\VobSub) (Version:  - )
VPNTunnel 2.0.1.0 (HKLM\...\VPNTunnel) (Version: 2.0.1.0 - )
VTFEdit 1.3.3 (HKLM\...\VTFEdit_is1) (Version:  - Neil Jedrzejewski & Ryan Gregg)
War Thunder Launcher 1.0.1.322 (HKLM\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version:  - 2013 Gaijin Entertainment Corporation)
WaveLab 6 (HKLM\...\WaveLabPro) (Version: 6.1.1.353 - Steinberg)
WebcamMax (HKLM\...\WebcamMax) (Version: 7.8.8.8.MultiLanguage - COOLWAREMAX)
Western Railway NV 3D Screensaver 2.0 (HKLM\...\Western Railway NV 3D Screensaver_is1) (Version: 2.0 - 3Planesoft)
Westwood Chat (HKLM\...\Westwood Chat_is1) (Version:  - )
WhoCrashed 5.03 (HKLM\...\WhoCrashed_is1) (Version:  - Resplendence Software Projects Sp.)
Winamp (HKLM\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows Live ID Sign-in Assistant (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows XP Mode (HKLM\...\{1374CC63-B520-4f3f-98E8-E9020BF01CFF}) (Version: 1.3.7600.16422 - Microsoft Corporation)
Wing Commander III (HKLM\...\{F96B9930-E22A-44D6-81B5-6C8E92C21B4B}) (Version: 2.0.0.2 - Electronic Arts)
Wings 3D 1.5.2 (HKLM\...\Wings 3D 1.5.2) (Version:  - )
WinPcap 4.1.3 (HKLM\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinPlay3 (HKLM\...\WinPlay3) (Version:  - )
WinRAR 5.01 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
WinSCP 5.5.1 (HKLM\...\winscp3_is1) (Version: 5.5.1 - Martin Prikryl)
Wireshark 1.12.3 (32-bit) (HKLM\...\Wireshark) (Version: 1.12.3 - The Wireshark developer community, hxxp://www.wireshark.org)
Wolfenstein 1.11(CREATED BY XEONKING©) (HKLM\...\Wolfenstein 1.11_is1) (Version:  - )
World Racing (HKLM\...\InstallShield_{B151F020-1DEE-4716-944F-2759FC3C51DA}) (Version: 1.01.01 - SYNETIC)
World Racing (Version: 1.01.01 - SYNETIC) Hidden
Worms Reloaded (HKLM\...\Worms Reloaded_is1) (Version:  - )
Wuala (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Wuala) (Version: 1.0.444.0 - LaCie)
x86crt (HKLM\...\{50CBA9D7-4A12-44CA-8E75-9FD7374FBD12}) (Version: 1.0.0 - Microsoft)
XEOX Gamepad SL-6556-BK (HKLM\...\{5E7F3FD4-503B-4451-B2EB-AC8C82DBA32F}) (Version: 1.00.0000 - )
XviD MPEG4 Video Codec (remove only) (HKLM\...\XviD MPEG4 Video Codec) (Version:  - )
yEd Graph Editor 3.13 (HKLM\...\3309-7404-0599-8908) (Version: 3.13 - yWorks GmbH)
You Don't Know Jack 4 1.00 (HKLM\...\You Don't Know Jack 4) (Version: 1.00 - Take 2 Interactive)
Your Freedom 20140128-01 (HKLM\...\Your_Deploy_0) (Version:  - )
Ys Origin English Edition v1.1 - Uninstallation (HKLM\...\Ys Origin English Edition v1.1 - Uninstallation) (Version:  - )
Zak McKracken - Between Time and Space (HKLM\...\Zak McKracken - Between Time and Space) (Version:  - )
Zattoo Live TV (HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\6d7aa3e3bf931c56) (Version: 1.0.0.47 - Zattoo Europa AG)
Zip Motion Block Video codec (Remove Only) (HKLM\...\ZMBV) (Version:  - DOSBox Team)
ZoneAlarm Antivirus (Version: 13.2.015.000 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Extreme Security (HKLM\...\ZoneAlarm Extreme Security) (Version: 13.2.015.000 - Check Point)
ZoneAlarm Find My Laptop (Version: 13.2.015.000 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Firewall (Version: 13.2.015.000 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Security (Version: 13.2.015.000 - Check Point Software Technologies Ltd.) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{07474513-7B58-45c7-B3E6-13A3669B1AFD}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{1c492e6a-2803-5ed7-83e1-1b1d4d41eb39}\InprocServer32 -> C:\Program Files\Ubisoft\Trials Evolution Gold Edition\datapack\orbit\npuplaypc.dll (Ubisoft)
CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{2BFFE1F1-509C-5018-A65D-701A661E27A7}\InprocServer32 -> C:\Users\Friedrich\AppData\Roaming\JPLNASAVTAD\NASAEyes\1.0.0.0\npNASAEyes.dll (JPL/NASA-Caltech)
CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{5b55a44a-d008-49aa-9234-86fb7709bc0a}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3642466463-2128021046-2334674927-1002_Classes\CLSID\{97D17A04-4438-4C8E-BAC7-BC21B8B9E999}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)

==================== Restore Points  =========================

25-03-2015 07:49:55 ComboFix created restore point

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-03-19 11:38 - 2015-03-25 05:16 - 00524831 ___RA C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 activate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip4.adobe.com
127.0.0.1 activate.wip4.adobe.com
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {77F35997-F6F3-4A1B-A6EF-DCB05DBF7FCB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-02-19] (Piriform Ltd)
Task: {8DBE0222-73D8-4AC7-BCD5-659CD14297A0} - System32\Tasks\{BF9086B8-0A25-4AB1-8F13-BBB7BC85052F} => pcalua.exe -a C:\Users\Friedrich\Desktop\setup.exe -d C:\Users\Friedrich\Desktop
Task: {F0EBA85F-D539-4520-B198-A26C60FF4DED} - System32\Tasks\{2B4B59FD-A0E1-438D-8B62-9502AF180507} => pcalua.exe -a "E:\Programme\Outlook Express\setup50.exe" -d "E:\Programme\Outlook Express"
Task: {F3596DCE-98A3-45AC-B9EC-3B5823977BDB} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Loaded Modules (whitelisted) ==============

2014-01-11 03:10 - 2015-02-05 19:27 - 00108864 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2014-08-25 12:15 - 2014-08-25 12:15 - 00022736 _____ () C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe
2014-03-16 05:52 - 2008-08-18 16:08 - 00050688 _____ () C:\Program Files\Virtual CD v10\System\ogg.dll
2014-03-16 05:52 - 2008-08-18 16:11 - 01237504 _____ () C:\Program Files\Virtual CD v10\System\vorbis.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-06-12 17:22 - 2014-06-12 17:22 - 01261272 _____ () C:\Program Files\VMware\VMware Workstation\libxml2.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:06A7F9ED
AlternateDataStreams: C:\ProgramData\TEMP:8FCD8443
AlternateDataStreams: C:\ProgramData\TEMP:A5B56640
AlternateDataStreams: C:\ProgramData\TEMP:DA5888A7
AlternateDataStreams: C:\ProgramData\TEMP:FB6A21E3

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.44.44

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-3642466463-2128021046-2334674927-500 - Administrator - Disabled)
Gast (S-1-5-21-3642466463-2128021046-2334674927-501 - Limited - Disabled)
Friedrich (S-1-5-21-3642466463-2128021046-2334674927-1002 - Administrator - Enabled) => C:\Users\Friedrich

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============
Error: (03/25/2015 07:57:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (03/25/2015 07:57:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (03/25/2015 07:57:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz
Percentage of memory in use: 39%
Total physical RAM: 3293.82 MB
Available physical RAM: 1977.87 MB
Total Pagefile: 3342.12 MB
Available Pagefile: 2122.2 MB
Total Virtual: 2047.88 MB
Available Virtual: 1890.57 MB

==================== Drives ================================

Drive c: (Lokaler Datenträger) (Fixed) (Total:2048 GB) (Free:89.55 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Medien Datenträger) (Fixed) (Total:1863.01 GB) (Free:332.27 GB) NTFS
Drive f: (Backup Datenträger RED 3TB) (Fixed) (Total:2048 GB) (Free:327.4 GB) NTFS
Drive h: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive i: (64bitGaming) (Fixed) (Total:1862.92 GB) (Free:1543.44 GB) NTFS
Drive x: (RamDisk) (Fixed) (Total:3.89 GB) (Free:3.8 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 379CF46E)
Partition 1: (Active) - (Size=2048 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 02962212)
Partition 1: (Not Active) - (Size=2048 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 0FD998DB)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1862.9 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (Size: 1863 GB) (Disk ID: 03AA03A9)
Partition 1: (Active) - (Size=1863 GB) - (Type=07 NTFS)

========================================================
Disk: 4 (Size: 3.9 GB) (Disk ID: BCB028AD)
Partition 1: (Not Active) - (Size=3.9 GB) - (Type=07 NTFS)

==================== End Of Log ============================

PS: Alle Anwendungen sind geschlossen, wenn diese Verbindungsversuche auftreten, manchmal passiert auch 10 min. nix, also das die host irgendwelche cashseiten connected.
beim systemstart ist mir aufgefallen dass als allererstes dedi97.sakuraserver.co und die host.bogiehosting.net seite aufgerufen wird. Habe ich natürlich auf die hosts-liste zum blocken gelegt.
Im Anhang (Screenshot) habe ich den prozess, über den die verbindungen zum zeitpunkt aufgebaut wurden, einmal Dargestellt.

schrauber 25.03.2015 18:39

Der Proxy in FF ist mit Absicht?

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
Emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.




Lade Dir bitte von hier Emsisoft Emergency Kit Download Emsisoft Emergency Kit herunter.
  • Bitte installiere das Programm in den vorgegebenen Pfad.
  • Starte das Programm durch Doppelklick der Desktopverknüpfung.
  • Das EEK ist nach dem Laden der Malwaresignaturen für den Scan bereit.
  • Folge nun bitte der bebilderten Bildanleitung zu Emergency Kit, entferne alle Funde und poste am Ende des Scans bzw. der Bereinigung das Log.


Friedrich_ 26.03.2015 15:15

Ja, Der Proxy ist Absicht!.

FRST Fix-LOG
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015
Ran by Friedrich at 2015-03-26 00:23:08 Run:1
Running from C:\Users\Friedrich\Desktop
Loaded Profiles: Friedrich (Available profiles: Friedrich)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
Emptytemp:
*****************

rpcapd => Service deleted successfully.
EmptyTemp: => Removed 109.3 MB temporary data.


The system needed a reboot.

==== End of Fixlog 00:23:14 ====

Code:

Emisoft Emergency Kit 9.0-LOG
Code:

Emsisoft Emergency Kit - Version 9.0
Letztes Update: 26.03.2015 00:38:30
Benutzerkonto: DSLSERVICE\Friedrich

Scan-Einstellungen:

Scan Methode: Detail-Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\, F:\, H:\, I:\, X:\

PUPs-Erkennung: An
Archiv-Scan: An
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: Aus

Scan-Beginn:        26.03.2015 00:52:35
C:\Users\Friedrich\AppData\Roaming\ActiveX\plugins\opencl\        gefunden: Trojan.Win32.Miner (A)
C:\Users\Friedrich\AppData\Roaming\ActiveX\plugins\phatk2\        gefunden: Trojan.Win32.Miner (A)
C:\Users\Friedrich\AppData\Roaming\ActiveX\ax.bat        gefunden: Trojan.Win32.Miner (A)
C:\Users\Friedrich\AppData\Roaming\ActiveX\phoenix.cfg        gefunden: Trojan.Win32.Miner (A)
Value: HKEY_USERS\S-1-5-21-3642466463-2128021046-2334674927-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR        gefunden: Setting.DisableTaskMgr (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS        gefunden: Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-21-3642466463-2128021046-2334674927-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS        gefunden: Setting.DisableRegistryTools (A)
C:\Program Files\CheckPoint\Install\CUninstallerZA.exe        gefunden: Application.Win32.InstallTool (A)
C:\Users\Friedrich\Desktop\nirsoft_package_1.19.21 150freewareprogramm im launcher.zip -> NirSoft/lsasecretsview.exe        gefunden: Application.Nirsoft.K (B)
C:\Users\Friedrich\Desktop\nirsoft_package_1.19.21 150freewareprogramm im launcher.zip -> NirSoft/mailpv.exe        gefunden: Gen:Variant.Application.NirSoft.1 (B)
C:\Users\Friedrich\Desktop\nirsoft_package_1.19.21 150freewareprogramm im launcher.zip -> NirSoft/mspass.exe        gefunden: Gen:Application.Heur.emKfkOTC9tdO (B)
C:\Users\Friedrich\Desktop\nirsoft_package_1.19.21 150freewareprogramm im launcher.zip -> NirSoft/netpass.exe        gefunden: Gen:Application.Heur.dmLfkmmPaPpO (B)
C:\Users\Friedrich\Desktop\nirsoft_package_1.19.21 150freewareprogramm im launcher.zip -> NirSoft/operapassview.exe        gefunden: Application.Nirsoft.K (B)
C:\Users\Friedrich\Desktop\nirsoft_package_1.19.21 150freewareprogramm im launcher.zip -> NirSoft/pstpassword.exe        gefunden: Gen:Application.Heur.cmKfkavUy1fO (B)
C:\Users\Friedrich\Desktop\nirsoft_package_1.19.21 150freewareprogramm im launcher.zip -> NirSoft/rdpv.exe        gefunden: Gen:Application.Heur.bmKfbW76vOjO (B)
C:\Users\Friedrich\Desktop\nirsoft_package_1.19.21 150freewareprogramm im launcher.zip -> NirSoft/routerpassview.exe        gefunden: Gen:Application.Heur.emLfk4FizegO (B)
C:\Users\Friedrich\Desktop\nirsoft_package_1.19.21 150freewareprogramm im launcher.zip -> NirSoft/vncpassview.exe        gefunden: Gen:Application.Heur.dq0@kyQo7tdO (B)
C:\Users\Friedrich\Desktop\nirsoft_package_1.19.21 150freewareprogramm im launcher.zip -> NirSoft/wirelesskeyview.exe        gefunden: Application.Nirsoft.K (B)
C:\Users\Public\Documents\RootGenius\29 -> 29.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\30 -> 30.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\31 -> 31.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\32 -> 32.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\34 -> 34.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\35 -> 35.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\40 -> 40.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\44 -> 44.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-20\cdr -> META-INF/CERT.RSA        gefunden: Android.Exploit.MasterKey.B (B)
C:\Users\Public\Documents\RootGenius\id-29\29.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-30\30.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-31\31.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-32\32.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-34\34.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-35\35.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-40\40.dll        gefunden: Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-44\44.dll        gefunden: Gen:Variant.Graftor.171318 (B)
I:\Program Files (x86)\CheckPoint\Install\CUninstaller.exe        gefunden: Application.Win32.InstallTool (A)
I:\Program Files\CheckPoint\ZAForceField\CUninstaller.exe        gefunden: Application.Win32.InstallTool (A)

Gescannt        1628000
Gefunden        37

Scan-Ende:        26.03.2015 06:37:43
Scan-Zeit:        5:45:08

C:\Users\Public\Documents\RootGenius\id-44\44.dll        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-40\40.dll        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-35\35.dll        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-34\34.dll        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-32\32.dll        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-31\31.dll        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-30\30.dll        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-29\29.dll        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\id-20\cdr        Quarantäne Android.Exploit.MasterKey.B (B)
C:\Users\Public\Documents\RootGenius\44        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\40        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\35        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\34        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\32        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\31        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\30        Quarantäne Gen:Variant.Graftor.171318 (B)
C:\Users\Public\Documents\RootGenius\29        Quarantäne Gen:Variant.Graftor.171318 (B)
Value: HKEY_USERS\S-1-5-21-3642466463-2128021046-2334674927-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS        Quarantäne Setting.DisableRegistryTools (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS        Quarantäne Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-21-3642466463-2128021046-2334674927-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR        Quarantäne Setting.DisableTaskMgr (A)
C:\Users\Friedrich\AppData\Roaming\ActiveX\phoenix.cfg        Quarantäne Trojan.Win32.Miner (A)
C:\Users\Friedrich\AppData\Roaming\ActiveX\ax.bat        Quarantäne Trojan.Win32.Miner (A)
C:\Users\Friedrich\AppData\Roaming\ActiveX\plugins\phatk2\        Quarantäne Trojan.Win32.Miner (A)
C:\Users\Friedrich\AppData\Roaming\ActiveX\plugins\opencl\        Quarantäne Trojan.Win32.Miner (A)

Quarantäne        24

Bis auf die False Positives(Nirsoft u. ZoneAlarm funde) habe ich alle in die Quarantäne geschoben.
Ich hatte es gehofft, aber leider war dieses Trojan.Win32.Miner aktiveX nicht für die svchost zugriffe zuständig :-(. Sie treten weiterhin auf.
mfg

PS: Ebenfalls wurde ich gestern abend von der Telekom-Abuse darüber informiert, das über meinen Anschluss spammails verschickt worden sind, dürfte wohl damit zusammenhängen. Im Moment zeigt wireshark aber kein verhalten an.

schrauber 26.03.2015 19:35

Alle Passwörter von einem andern Rechner aus ändern. Dann schauen wir mal von aussen:

Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST Download FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Ja und klicke Untersuchen
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).


Friedrich_ 26.03.2015 22:51

re6
 
Hallo,
den Wechseldatenträger habe ich mittels "wmic logicaldisk get deviceid, volumename, description" als DOS befehl ausfindig gemacht.
Die Option Computer reparieren erschien nur beim booten über die CD. (nicht über F8)

FRST Bootscan-LOG

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by SYSTEM on MININT-G1E912R on 26-03-2015 22:35:41
Running from I:\
Platform: Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [VC10Player] => C:\Program Files\Virtual CD v10\System\VC10Play.exe [411976 2011-10-19] (H+H Software GmbH)
HKLM\...\Run: [USB3MON] => C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM\...\Run: [ISW] => C:\Program Files\CheckPoint\AKL\AkSA.exe [638584 2014-05-14] (Check Point Software Technologies LTD)
HKLM\...\Run: [LifeCam] => C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\Run: [Razer Synapse] => C:\Program Files\Razer\Synapse\RzSynapse.exe [590144 2015-02-28] (Razer Inc.)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [153672 2010-06-14] (Logitech Inc.)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\Friedrich\...\Run: [DMS-Kalenderchen] => C:\Program Files\Kalenderchen\Kalenderchen.exe [3498496 2010-05-18] (Daniel Manger Software)
HKU\Friedrich\...\Policies\system: [LogonHoursAction] 2
HKU\Friedrich\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\allSnap.lnk
ShortcutTarget: allSnap.lnk -> C:\Program Files\allSnap\allSnap.exe (Ivan Heckman)
SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll (Stardock.net, Inc)
BootExecute: autocheck autochk * OODBS

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-20] ()
S4 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [70952 2011-03-31] (CyberLink)
S4 CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [312616 2011-03-31] (CyberLink)
S2 DokanMounter; C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe [22736 2014-08-25] ()
S4 EMET_Service; C:\Program Files\EMET 5.1\EMET_Service.exe [31880 2014-11-09] (Microsoft Corporation)
S3 Futuremark SystemInfo Service; C:\Program Files\Futuremark\SystemInfo\FMSISvc.exe [614624 2015-02-09] (Futuremark)
S3 ICCS; C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation)
S3 IswSvc; C:\Program Files\CheckPoint\AKL\AkSVC.exe [749176 2014-05-14] (Check Point Software Technologies LTD)
S4 mfevtp; C:\Windows\system32\mfevtps.exe [238288 2015-03-23] (McAfee, Inc.)
S2 nlndis; C:\Program Files\NetLimiter Ndis Miniport Service\nlndis.exe [32768 2011-10-05] (Locktime Software)
S3 nlsvc; C:\Program Files\NetLimiter 3\nlsvc.exe [1126400 2013-02-20] (Locktime Software)
S2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2505160 2013-01-07] (O&O Software GmbH)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [32568 2014-08-07] (The OpenVPN Project)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1910640 2015-03-04] (Electronic Arts)
S4 Razer Game Scanner Service; C:\Program Files\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-02-05] ()
S3 Realtek87B; C:\Program Files\Realtek\RTL8187 Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek)
S3 RUBotSrv; C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe [443416 2013-07-25] (Trend Micro Inc.)
S4 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [1998672 2015-02-05] (Crawler Group)
S2 VC10SecS; C:\Program Files\Virtual CD v10\System\VC10SecS.exe [144712 2011-10-19] (H+H Software GmbH)
S2 VMAuthdService; C:\Program Files\VMware\VMware Workstation\vmware-authd.exe [86744 2014-06-12] (VMware, Inc.)
S2 VMnetDHCP; C:\Windows\system32\vmnetdhcp.exe [359128 2014-06-12] (VMware, Inc.)
S2 VMUSBArbService; C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [722624 2014-02-27] (VMware, Inc.)
S2 VMware NAT Service; C:\Windows\system32\vmnat.exe [437976 2014-06-12] (VMware, Inc.)
S2 VMwareHostd; C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe [14407384 2014-06-12] ()
S3 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3592120 2014-05-30] (Check Point Software Technologies Ltd.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S4 WZCOOK; C:\Users\Friedrich\Desktop\Exploit Sets\aircrack 2.1\win32\wzcook.exe [40960 2004-10-01] ()
S2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [90936 2014-05-29] (Check Point Software Technologies, Ltd.)
S2 ZoneAlarm AntiTheft; C:\Program Files\CheckPoint\AntiTheft\Antitheft.exe [3128968 2014-05-30] (Check Point Software Technologies Ltd.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 cleanhlp; C:\EEK\bin\cleanhlp32.sys [50200 2015-03-25] (Emsisoft GmbH)
S3 CrystalSysInfo; C:\Program Files\MediaCoder\SysInfo.sys [15152 2007-09-25] ()
S2 Dokan; C:\Windows\system32\drivers\dokan.sys [105680 2014-08-25] (Windows (R) Win 7 DDK provider)
S3 ENTECH; C:\Windows\system32\DRIVERS\ENTECH.sys [21664 2004-10-25] (EnTech Taiwan)
S3 es1371; C:\Windows\System32\drivers\es1371mp.sys [40832 2002-06-03] (Creative Technology Ltd.)
S0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] ()
S3 GKBFltr; C:\Windows\System32\Drivers\GameKB.sys [19328 2009-12-29] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S2 hcmon; C:\Windows\system32\drivers\hcmon.sys [43840 2014-02-27] (VMware, Inc.)
S3 HH10Help.sys; C:\Windows\system32\drivers\HH10Help.sys [13952 2010-03-10] (H+H Software GmbH)
S0 iaStorA; C:\Windows\System32\drivers\iaStorA.sys [532536 2012-09-01] (Intel Corporation)
S0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [25656 2012-09-01] (Intel Corporation)
S3 icsak; C:\Program Files\CheckPoint\AKL\ak\icsak.sys [39296 2014-05-14] (Check Point Software Technologies LTD)
S2 ISWKL; C:\Program Files\CheckPoint\AKL\ISWKL.sys [42880 2014-05-14] (Check Point Software Technologies LTD)
S0 iusb3hcs; C:\Windows\System32\drivers\iusb3hcs.sys [16880 2013-02-22] (Intel Corporation)
S3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [352752 2013-02-22] (Intel Corporation)
S3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [796656 2013-02-22] (Intel Corporation)
S0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-04-30] (Kaspersky Lab ZAO)
S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [488032 2014-04-30] (Kaspersky Lab ZAO)
S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2014-04-30] (Kaspersky Lab ZAO)
S1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [43608 2014-04-30] (Kaspersky Lab)
S1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144352 2014-04-30] (Kaspersky Lab ZAO)
S3 MBfilt; C:\Windows\System32\drivers\MBfilt32.sys [24664 2009-11-18] (Creative Technology Ltd.)
S3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-02] (Intel Corporation)
S0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [648552 2015-03-23] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [91840 2015-03-23] (McAfee, Inc.)
S3 NLNdisMP; C:\Windows\System32\DRIVERS\nlndis.sys [5230088 2011-03-21] (Locktime Software)
S3 NLNdisPT; C:\Windows\System32\DRIVERS\nlndis.sys [5230088 2011-03-21] (Locktime Software)
S1 nltdi; C:\Program Files\NetLimiter 3\nltdi.sys [5281672 2011-03-21] (Locktime Software)
S2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S2 ntk_PowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [71664 2011-04-20] (Cyberlink Corp.)
S2 ParagonLDM; C:\Windows\system32\drivers\biont_bs.sys [24512 2014-04-11] (Paragon Software GmbH)
S3 pneteth; C:\Windows\System32\DRIVERS\pneteth.sys [13440 2011-11-24] (June Fabrics Technology Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
S3 RTCore32; C:\Program Files\MSI Afterburner\RTCore32.sys [5632 2013-03-11] ()
S3 RTL8187; C:\Windows\System32\DRIVERS\rtl8187.sys [375808 2010-01-07] (Realtek Semiconductor Corporation                          )
S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [35624 2014-12-17] (Razer Inc)
S2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [20416 2015-02-05] (Razer, Inc.)
S2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [97088 2014-11-17] (Razer, Inc.)
S3 rzudd; C:\Windows\System32\DRIVERS\rzudd.sys [151336 2014-12-30] (Razer Inc)
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP2\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware)
S0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software)
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [436792 2013-01-30] (Duplex Secure Ltd.)
S1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] ()
S0 SscRdBus; C:\Windows\System32\DRIVERS\SscRdBus.sys [88296 2014-11-22] (SuperSpeed LLC)
S0 SscRdCls; C:\Windows\System32\DRIVERS\SscRdCls.sys [40984 2007-12-19] (SuperSpeed LLC)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [23040 2014-04-08] (The OpenVPN Project)
S3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [5120 2012-12-19] ()
S1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [91016 2013-12-26] ()
S1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [20616 2013-12-26] ()
S1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [540168 2013-12-26] ()
S1 Uim_Vim; C:\Windows\System32\Drivers\Uim_Vim.sys [283600 2012-11-22] (Paragon)
S1 vdrv1000; C:\Windows\System32\DRIVERS\vdrv1000.sys [186392 2011-04-19] (H+H Software GmbH)
S3 vmkbd2; C:\Windows\system32\drivers\VMkbd.sys [26456 2014-06-12] (VMware, Inc.)
S3 VMnetAdapter; C:\Windows\System32\DRIVERS\vmnetadapter.sys [17104 2014-06-12] (VMware, Inc.)
S2 VMnetBridge; C:\Windows\System32\DRIVERS\vmnetbridge.sys [37456 2014-06-12] (VMware, Inc.)
S2 VMnetuserif; C:\Windows\system32\drivers\vmnetuserif.sys [26968 2014-06-12] (VMware, Inc.)
S2 vmx86; C:\Windows\system32\Drivers\vmx86.sys [66136 2014-06-12] (VMware, Inc.)
S3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [172416 2010-11-20] (Microsoft Corporation)
S1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [48128 2010-11-20] (Microsoft Corporation)
S3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2010-11-20] (Microsoft Corporation)
S1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [296064 2010-11-20] (Microsoft Corporation)
S1 Vsdatant; C:\Windows\System32\drivers\vsdatant.sys [456088 2014-05-30] (Check Point Software Technologies Ltd.)
S0 vsock; C:\Windows\System32\drivers\vsock.sys [63824 2013-10-08] (VMware, Inc.)
S2 vstor2-mntapi20-shared; C:\Windows\System32\drivers\vstor2-mntapi20-shared.sys [23632 2013-02-22] (VMware, Inc.)
S2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam.sys [1068216 2012-04-15] (Windows (R) Win 7 DDK provider)
S3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22856 2010-04-27] (Logitech Inc.)
S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [37704 2010-04-27] (Logitech Inc.)
S3 WmHidLo; C:\Windows\System32\drivers\WmHidLo.sys [31816 2010-04-27] (Logitech Inc.)
S3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [15048 2010-04-27] (Logitech Inc.)
S3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66632 2010-04-27] (Logitech Inc.)
S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [465408 2009-07-14] (Microsoft Corporation)
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [77296 2011-04-12] (CyberLink Corp.)
S3 catchme; \??\C:\Users\HAKENN~1\AppData\Local\Temp\catchme.sys [X]
S5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2014-04-30] (Kaspersky Lab ZAO)
S4 NvStUSB; \SystemRoot\system32\drivers\nvstusb.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-26 15:52 - 2015-03-26 15:52 - 00008538 _____ () C:\Users\Friedrich\Desktop\RKreport_SCN_03262015_154713.log
2015-03-26 15:31 - 2015-03-26 15:43 - 00035064 _____ () C:\Windows\System32\Drivers\TrueSight.sys
2015-03-26 15:31 - 2015-03-26 15:41 - 00000000 ____D () C:\ProgramData\RogueKiller
2015-03-26 00:33 - 2015-03-26 14:57 - 00000000 ____D () C:\EEK
2015-03-25 22:21 - 2015-03-25 22:22 - 18058361 _____ () C:\Users\Friedrich\Desktop\Roguekiller_10.5.7.zip
2015-03-25 22:20 - 2015-03-25 22:21 - 21096344 _____ (SUPERAntiSpyware) C:\Users\Friedrich\Desktop\SUPERAntiSpyware.exe
2015-03-25 22:17 - 2015-03-25 22:22 - 163616472 _____ () C:\Users\Friedrich\Desktop\EmsisoftEmergencyKit.exe
2015-03-25 08:46 - 2015-03-25 08:55 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Find-it
2015-03-25 08:45 - 2015-03-25 08:45 - 00296960 _____ (Microsoft Corporation) C:\Windows\winhlp32.TAK
2015-03-23 09:32 - 2015-03-23 09:33 - 00000000 ____D () C:\Program Files\MiniTool Partition Wizard Free 9.0
2015-03-23 08:20 - 2015-03-23 08:20 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-03-23 06:22 - 2015-03-23 06:22 - 00648552 _____ (McAfee, Inc.) C:\Windows\System32\Drivers\mfehidk.sys
2015-03-23 06:22 - 2015-03-23 06:22 - 00238288 _____ (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
2015-03-23 06:22 - 2015-03-23 06:22 - 00091840 _____ (McAfee, Inc.) C:\Windows\System32\Drivers\mferkdet.sys
2015-03-23 03:20 - 2015-03-25 07:46 - 00000000 ____D () C:\Windows\erdnt
2015-03-23 03:07 - 2015-03-26 22:35 - 00000000 ____D () C:\FRST
2015-03-23 02:18 - 2015-03-23 09:37 - 00172576 _____ () C:\Users\Friedrich\Documents\pinfect.zip
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\VDLL.DLL
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\System32\runouce.exe
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\RUNDL132.EXE
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\logo_1.exe
2015-03-23 00:29 - 2015-03-23 09:36 - 00000054 _____ () C:\Windows\Lic.xxx
2015-03-23 00:29 - 2015-03-23 00:29 - 00034048 _____ (MicroWorld Technologies Inc.) C:\Windows\System32\eEmpty.exe
2015-03-23 00:29 - 2015-03-23 00:29 - 00000000 ____D () C:\ProgramData\MicroWorld
2015-03-23 00:29 - 2015-03-23 00:29 - 00000000 ____D () C:\Program Files\Common Files\MicroWorld
2015-03-23 00:29 - 2005-09-22 23:22 - 00000522 _____ () C:\Windows\System32\Microsoft.VC80.CRT.manifest
2015-03-23 00:22 - 2015-03-26 14:54 - 00000000 ____D () C:\Users\Friedrich\Desktop\Sammlung fürs Board
2015-03-22 20:37 - 2015-03-22 20:37 - 00000000 ____D () C:\ProgramData\Trend Micro
2015-03-22 19:00 - 2015-03-22 19:00 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-03-22 18:29 - 2015-03-22 18:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-20 23:13 - 2015-03-20 23:13 - 00000000 ____D () C:\Program Files\Trend Micro
2015-03-20 22:57 - 2015-03-20 22:57 - 00000000 ____D () C:\Program Files\Emsisoft HiJackFree
2015-03-20 19:07 - 2015-03-20 19:11 - 00000000 ____D () C:\TDSSKiller_Quarantine
2015-03-19 01:28 - 2015-03-19 02:52 - 00000000 ____D () C:\Users\Friedrich\Desktop\ThinkpadpunkteVideo
2015-03-19 00:53 - 2015-03-22 19:01 - 00429152 _____ () C:\Users\Friedrich\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-19 00:52 - 2015-03-22 19:12 - 04703120 _____ () C:\Windows\System32\FNTCACHE.DAT
2015-03-18 21:39 - 2010-04-07 02:29 - 00081920 _____ () C:\Windows\System32\GkSui20.EXE
2015-03-18 21:26 - 2015-03-16 18:44 - 00749664 _____ (Oracle Corporation) C:\Windows\System32\Drivers\VBoxDrv.sys
2015-03-18 21:25 - 2015-03-18 21:25 - 00000000 ____D () C:\Program Files\Oracle
2015-03-18 21:25 - 2015-03-16 18:42 - 00104384 _____ (Oracle Corporation) C:\Windows\System32\Drivers\VBoxUSBMon.sys
2015-03-18 21:17 - 2015-03-18 21:17 - 00000000 ____D () C:\Windows\System32\RTCOM
2015-03-18 21:16 - 2014-12-03 13:51 - 00927960 _____ (Realtek Semiconductor Corp.) C:\Windows\System32\RtkCoInstII.dll
2015-03-18 21:16 - 2014-12-03 11:41 - 03365208 _____ (Realtek Semiconductor Corp.) C:\Windows\System32\Drivers\RTKVHDA.sys
2015-03-18 21:16 - 2014-12-03 10:15 - 01485163 _____ () C:\Windows\System32\Drivers\RTAIODAT.DAT
2015-03-18 21:16 - 2014-12-02 11:42 - 02381680 _____ (Realtek Semiconductor Corp.) C:\Windows\System32\RtkApoApi.dll
2015-03-18 21:16 - 2014-11-27 08:31 - 02510192 _____ (Realtek Semiconductor Corp.) C:\Windows\System32\RltkAPO.dll
2015-03-18 21:16 - 2014-08-06 06:43 - 02588888 _____ (Realtek Semiconductor Corp.) C:\Windows\System32\RtkPgExt.dll
2015-03-18 21:16 - 2014-04-10 05:19 - 01940056 _____ (Waves Audio Ltd.) C:\Windows\System32\MaxxAudioEQ.dll
2015-03-18 21:16 - 2014-03-06 09:35 - 01892056 _____ (Realtek Semiconductor Corp.) C:\Windows\System32\RTSndMgr.cpl
2015-03-18 21:16 - 2014-02-18 10:04 - 02421792 _____ (Fortemedia Corporation) C:\Windows\System32\FMAPO.dll
2015-03-18 21:16 - 2014-01-08 08:25 - 00332568 _____ (Creative Technology Ltd.) C:\Windows\System32\MBWrp32.dll
2015-03-18 21:16 - 2013-01-11 09:27 - 00563992 _____ (Creative Technology Ltd.) C:\Windows\System32\MBTHX32.dll
2015-03-18 21:16 - 2011-11-22 09:28 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\System32\RtkCoLDR.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\System32\RTEEP32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\System32\RP3DHT32.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\System32\RP3DAA32.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\System32\RTEED32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\System32\RTEEL32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\System32\RTEEG32A.dll
2015-03-18 21:16 - 2010-09-27 02:34 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\System32\MaxxAudioAPO20.dll
2015-03-18 21:16 - 2009-12-04 08:43 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\System32\MaxxAudioAPO.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\System32\SRSTSXT.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\System32\SRSTSHD.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\System32\SRSHP360.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\System32\SRSWOW.dll
2015-03-18 21:16 - 2009-11-18 11:42 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\System32\WavesLib.dll
2015-03-18 21:16 - 2009-11-18 00:12 - 00024664 _____ (Creative Technology Ltd.) C:\Windows\System32\Drivers\MBfilt32.sys
2015-03-18 21:15 - 2014-06-06 17:00 - 00519368 _____ (Andrea Electronics Corporation) C:\Windows\System32\AERTACap.dll
2015-03-18 21:15 - 2013-10-11 05:47 - 00092584 _____ (Real Sound Lab SIA) C:\Windows\System32\CONEQMSAPOGUILibrary.dll
2015-03-18 21:15 - 2012-03-08 04:47 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\System32\AERTARen.dll
2015-03-18 20:49 - 2015-01-25 11:20 - 00000000 ____D () C:\Users\Friedrich\Desktop\Baphomets Fluch 1-5 Deutsch
2015-03-17 14:44 - 2015-03-18 17:10 - 329252864 _____ () C:\Users\Friedrich\Desktop\openSUSE-13.2-DVD-i586.iso
2015-03-17 14:37 - 2015-03-17 14:41 - 79691776 _____ () C:\Users\Friedrich\Desktop\CorePlus-current.iso
2015-03-16 18:42 - 2015-03-16 18:42 - 00115672 _____ (Oracle Corporation) C:\Windows\System32\Drivers\VBoxNetAdp.sys
2015-03-12 15:27 - 2015-03-26 15:53 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Everything
2015-03-11 20:41 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\System32\msi.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\System32\WsmSvc.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\System32\WSManMigrationPlugin.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\System32\WsmWmiPl.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\System32\WsmAuto.dll
2015-03-11 20:41 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\System32\WSManHTTPConfig.exe
2015-03-11 20:41 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\System32\TSWorkspace.dll
2015-03-11 20:02 - 2015-03-06 06:15 - 00137656 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2015-03-11 20:02 - 2015-03-06 06:15 - 00067512 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2015-03-11 20:02 - 2015-03-06 06:10 - 01061376 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00100352 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00015872 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2015-03-11 20:02 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
2015-03-11 20:02 - 2015-03-06 06:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2015-03-11 20:02 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
2015-03-11 20:02 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
2015-03-11 20:02 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
2015-03-11 20:02 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2015-03-11 20:02 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2015-03-11 20:02 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2015-03-11 20:02 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2015-03-11 20:02 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2015-03-11 20:02 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2015-03-11 20:02 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2015-03-11 20:02 - 2015-02-20 03:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2015-03-11 20:02 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2015-03-11 20:02 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2015-03-11 20:02 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2015-03-11 20:02 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2015-03-11 20:02 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2015-03-11 20:02 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2015-03-11 20:02 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2015-03-11 20:02 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2015-03-11 20:02 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2015-03-11 20:02 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2015-03-11 20:02 - 2015-02-20 02:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2015-03-11 20:02 - 2015-02-20 02:50 - 00667648 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2015-03-11 20:02 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-03-11 20:02 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2015-03-11 20:02 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2015-03-11 20:02 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2015-03-11 20:02 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2015-03-11 20:02 - 2015-02-20 02:24 - 00684544 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2015-03-11 20:02 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2015-03-11 20:02 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2015-03-11 20:02 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2015-03-11 20:02 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2015-03-11 20:02 - 2015-01-31 00:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2015-03-11 20:02 - 2015-01-29 04:05 - 03973048 _____ (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2015-03-11 20:02 - 2015-01-29 04:05 - 03917752 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
2015-03-11 20:02 - 2015-01-29 04:01 - 00262656 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00069632 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
2015-03-11 20:02 - 2015-01-29 04:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2015-03-11 20:02 - 2015-01-29 03:57 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll
2015-03-11 20:01 - 2015-02-26 04:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2015-03-11 20:01 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\System32\fontsub.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\System32\atmlib.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\System32\lpk.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\System32\dciman32.dll
2015-03-11 20:01 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2015-03-11 20:01 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
2015-03-11 20:01 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll
2015-03-11 20:01 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2015-03-11 20:01 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\System32\ubpm.dll
2015-03-11 20:01 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\System32\msctf.dll
2015-03-11 20:00 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\System32\scesrv.dll
2015-03-11 17:12 - 2007-08-13 14:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\System32\wmvdmoe.dll
2015-03-11 16:57 - 2015-03-11 17:03 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\WebcamZoneTrigger
2015-03-11 16:12 - 2015-03-11 16:12 - 00000000 ____D () C:\Users\Public\Documents\Xeoma
2015-03-11 12:19 - 2015-03-11 12:19 - 00000000 ____D () C:\Windows\System32\DCS
2015-03-11 01:10 - 2015-03-11 01:10 - 00003584 _____ () C:\Users\Friedrich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-08 10:55 - 2015-03-08 10:55 - 06208736 _____ (Tim Kosse) C:\Users\Friedrich\Downloads\FileZilla_3.10.2_win32-setup.exe
2015-03-08 10:55 - 2015-03-08 10:55 - 06057862 _____ (Tim Kosse) C:\Users\Friedrich\Downloads\FileZilla_3.9.0.5_win32-setup.exe
2015-03-08 03:47 - 2015-03-08 03:47 - 00000216 _____ () C:\Users\Friedrich\Desktop\rFactor Demo.url
2015-03-08 02:02 - 2015-03-08 02:02 - 00000000 ____D () C:\Program Files\LEGO Batman 3 - Beyond Gotham
2015-03-06 05:12 - 2015-03-06 05:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Apple Computer
2015-03-06 05:10 - 2015-03-06 05:12 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-03-06 05:08 - 2015-03-21 19:35 - 00000000 ____D () C:\Users\Friedrich\Desktop\LightWorks DE Tutorials
2015-03-06 04:28 - 2015-03-06 04:28 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-03-05 21:53 - 2015-03-05 21:53 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Stardock
2015-03-05 20:41 - 2015-03-13 19:42 - 00000000 ____D () C:\Users\Friedrich\Desktop\Chromanova.fm  - crazy freak dance 24-7-
2015-03-05 07:50 - 2015-03-05 07:50 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\com.ohnoo.TormentumDemo
2015-03-05 07:31 - 2015-03-05 07:31 - 00000000 ____D () C:\Users\Friedrich\Documents\SpriteLamp
2015-03-05 07:31 - 2015-03-05 07:31 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\SpriteLampWinforms
2015-03-05 06:58 - 2015-03-05 07:03 - 00000000 ____D () C:\Program Files\TClock
2015-03-05 06:04 - 2015-03-05 06:04 - 00000000 ____D () C:\Windows Anmeldesounds +Icons AlleSys Bildschirmschoner
2015-03-05 05:49 - 2015-03-05 05:49 - 00000000 ____D () C:\ProgramData\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 __HDC () C:\ProgramData\{9C3F823B-4738-4CAF-A6B2-69E87FB636C0}
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\Users\Public\Documents\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\Program Files\Stardock
2015-03-05 05:28 - 2015-03-05 05:28 - 00000000 ____D () C:\Program Files\MPU
2015-03-05 05:20 - 2015-03-05 05:20 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Lern-o-Mat
2015-03-05 05:14 - 2015-03-05 05:14 - 00000000 ____D () C:\Program Files\DVDlabPro2
2015-03-05 05:13 - 2015-03-05 05:13 - 00000000 ____D () C:\Program Files\Doc Scrubber
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\jStrip
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\Program Files\jStrip
2015-03-05 05:12 - 1999-10-30 02:00 - 00167936 _____ (Common Controls Replacement Project (CCRP)) C:\Windows\System32\ccrpftv6.ocx
2015-03-04 06:03 - 2015-03-12 12:34 - 00000000 ____D () C:\Users\Friedrich\.mediathek3
2015-03-04 06:03 - 2015-03-04 06:03 - 00000000 ____D () C:\Program Files\Mediathekview
2015-03-03 19:32 - 2015-03-03 19:32 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2015-03-03 18:52 - 2015-03-03 18:54 - 63361024 _____ () C:\Users\Friedrich\Desktop\EpicGamesLauncherInstaller-2.0.0-2465596.msi
2015-03-02 07:05 - 2015-03-02 07:05 - 00000000 ____D () C:\Users\Friedrich\Documents\Bandicam
2015-03-02 07:04 - 2015-03-23 16:41 - 00000000 ____D () C:\Program Files\Bandicam
2015-03-02 07:04 - 2015-03-02 07:04 - 00000000 ____D () C:\Program Files\BandiMPEG1
2015-03-01 23:52 - 2015-03-01 23:52 - 00000000 ____D () C:\Users\Friedrich\Desktop\Silent Hill Downpour (Xbox 360 Gamerip)
2015-02-28 18:06 - 2015-02-05 18:51 - 00621384 _____ (NVIDIA Corporation) C:\Windows\System32\nvStreaming.exe
2015-02-28 18:05 - 2015-02-05 21:48 - 24768144 _____ (NVIDIA Corporation) C:\Windows\System32\nvoglv32.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 20465808 _____ (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 16016848 _____ (NVIDIA Corporation) C:\Windows\System32\nvwgf2um.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 10773520 _____ (NVIDIA Corporation) C:\Windows\System32\nvopencl.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 10713256 _____ (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 08473928 _____ (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2015-02-28 18:05 - 2015-02-05 21:48 - 03247248 _____ (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 01047880 _____ (NVIDIA Corporation) C:\Windows\System32\nvdispco3234752.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00931136 _____ (NVIDIA Corporation) C:\Windows\System32\NvIFR.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00912528 _____ (NVIDIA Corporation) C:\Windows\System32\nvdispgenco3234752.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00909120 _____ (NVIDIA Corporation) C:\Windows\System32\NvFBC.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00877816 _____ (NVIDIA Corporation) C:\Windows\System32\nvumdshim.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00399504 _____ (NVIDIA Corporation) C:\Windows\System32\nvEncodeAPI.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00345928 _____ (NVIDIA Corporation) C:\Windows\System32\NvIFROpenGL.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00305136 _____ (NVIDIA Corporation) C:\Windows\System32\nvoglshim32.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00164568 _____ (NVIDIA Corporation) C:\Windows\System32\nvinit.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00161424 _____ (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda32v.sys
2015-02-28 18:05 - 2015-02-05 21:48 - 00027280 _____ (NVIDIA Corporation) C:\Windows\System32\nvhdap32.dll
2015-02-27 16:04 - 2015-02-27 19:00 - 00000000 ____D () C:\Program Files\EMET 5.1
2015-02-27 03:00 - 2015-02-27 03:00 - 00000216 _____ () C:\Users\Friedrich\Desktop\Tormentum - Dark Sorrow Demo.url
2015-02-26 18:36 - 2015-02-26 18:36 - 00000000 ____D () C:\Program Files\Cain
2015-02-24 19:24 - 2015-03-20 23:09 - 00000000 ____D () C:\Users\Friedrich\Documents\Survarium

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-26 22:28 - 2013-01-29 18:50 - 01308000 _____ () C:\Windows\WindowsUpdate.log
2015-03-26 22:27 - 2013-01-30 06:57 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\NetSpeedMonitor
2015-03-26 21:03 - 2009-07-14 05:34 - 00034848 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-26 21:03 - 2009-07-14 05:34 - 00034848 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-26 20:55 - 2013-02-17 07:38 - 00000000 ____D () C:\ProgramData\VMware
2015-03-26 20:54 - 2014-07-03 02:07 - 00068018 _____ () C:\Windows\setupact.log
2015-03-26 20:54 - 2014-01-11 03:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-03-26 20:54 - 2013-01-30 08:01 - 01854028 _____ () C:\Windows\System32\oodbs.lor
2015-03-26 17:12 - 2013-01-30 01:23 - 00000000 ____D () C:\Users\Friedrich\Desktop\Sicherheitsprogramme
2015-03-26 17:11 - 2013-01-30 08:07 - 00000000 ____D () C:\Program Files\Steam
2015-03-26 17:07 - 2013-03-02 16:35 - 00000000 ____D () C:\Program Files\Pluto Client
2015-03-26 16:54 - 2013-01-30 01:31 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\KeePass
2015-03-26 15:57 - 2013-01-29 23:37 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-26 15:23 - 2013-01-30 04:08 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\vlc
2015-03-26 09:21 - 2014-09-12 18:50 - 00000000 ____D () C:\Users\Public\Documents\RootGenius
2015-03-26 09:21 - 2013-03-13 02:29 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\ActiveX
2015-03-26 05:07 - 2013-01-30 01:23 - 00000000 ____D () C:\Users\Friedrich\Desktop\Exploit Sets
2015-03-26 00:10 - 2013-01-30 05:14 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\CrashDumps
2015-03-25 23:44 - 2013-11-22 18:50 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\AIMP3
2015-03-25 23:40 - 2013-02-06 01:52 - 00000000 ____D () C:\Program Files\THQ
2015-03-25 23:40 - 2013-01-30 02:18 - 00000000 ____D () C:\Users\Friedrich\Desktop\Spiele
2015-03-25 23:29 - 2010-11-20 22:01 - 01639348 _____ () C:\Windows\System32\PerfStringBackup.INI
2015-03-25 22:52 - 2013-01-30 06:49 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2015-03-25 22:49 - 2013-01-30 06:48 - 00000000 ____D () C:\Program Files\Spyware Terminator
2015-03-25 10:18 - 2014-07-05 01:41 - 00607810 _____ () C:\Windows\PFRO.log
2015-03-25 10:17 - 2013-02-05 00:25 - 00000000 ____D () C:\Program Files\stinger
2015-03-25 10:12 - 2013-06-04 01:27 - 00000000 ____D () C:\Stinger_Quarantine
2015-03-25 07:37 - 2014-07-05 01:31 - 00000000 ____D () C:\AdwCleaner
2015-03-25 06:56 - 2014-11-15 20:35 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys
2015-03-25 06:54 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Registration
2015-03-23 20:12 - 2014-01-11 01:33 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Apps\2.0
2015-03-23 20:12 - 2009-07-14 03:37 - 00000000 ___RD () C:\users\Public
2015-03-23 20:08 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2015-03-23 16:50 - 2013-02-11 06:02 - 00000000 ____D () C:\Users\Friedrich\Desktop\Magic.Games.II
2015-03-23 16:41 - 2013-01-30 06:17 - 00000000 ____D () C:\Program Files\mIRC
2015-03-23 16:39 - 2013-02-18 03:52 - 00000000 ____D () C:\Program Files\Dead Space 3 Limited Edition uncut
2015-03-23 16:39 - 2013-02-09 08:44 - 00000000 ____D () C:\Program Files\Magic The Gathering - Duels of the Planeswalkers
2015-03-23 16:39 - 2013-02-04 05:20 - 00000000 ____D () C:\Program Files\Serials World
2015-03-23 16:38 - 2014-01-29 18:03 - 00000000 ____D () C:\Program Files\DLH98
2015-03-23 16:37 - 2013-01-31 03:54 - 00000000 ____D () C:\Program Files\DiRT 3
2015-03-23 16:34 - 2014-07-06 04:05 - 00000000 ____D () C:\Program Files\Assetto Corsa
2015-03-23 16:34 - 2013-02-11 03:53 - 00000000 ____D () C:\Program Files\Ricochet Infinity
2015-03-23 16:33 - 2014-06-12 00:18 - 00000000 ____D () C:\Program Files\HD Video Repair Utility
2015-03-23 16:33 - 2013-03-02 16:32 - 00000000 ____D () C:\Program Files\Portrait Professional Studio 9
2015-03-23 08:21 - 2013-01-30 01:20 - 00042334 _____ () C:\Users\Friedrich\NeueDatenbank.kdbx
2015-03-23 08:21 - 2013-01-29 18:50 - 00000000 ____D () C:\users\Friedrich
2015-03-23 06:15 - 2014-03-23 15:43 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-03-23 06:00 - 2014-03-23 15:42 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamchameleon.sys
2015-03-23 04:16 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\System32\NDF
2015-03-23 02:47 - 2014-11-16 21:36 - 00000000 ____D () C:\Program Files\Spezial 5.0
2015-03-22 22:33 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-03-22 22:10 - 2013-01-30 01:23 - 00000000 ____D () C:\Users\Friedrich\Desktop\Weitere Programme
2015-03-22 21:36 - 2013-01-30 06:18 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\NoNameScript
2015-03-22 20:24 - 2014-10-20 17:53 - 00000000 ____D () C:\ProgramData\GalaxyClient
2015-03-22 19:59 - 2013-01-30 06:17 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\mIRC
2015-03-22 19:03 - 2013-01-30 03:24 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-22 18:56 - 2014-05-14 17:55 - 00000000 ____D () C:\Users\Friedrich\Desktop\Rap Mai 2014
2015-03-22 18:44 - 2013-02-06 04:46 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-22 18:23 - 2014-02-07 14:18 - 00000600 _____ () C:\Users\Friedrich\AppData\Roaming\winscp.rnd
2015-03-22 18:10 - 2014-08-20 05:17 - 00000000 ____D () C:\Windows\Minidump
2015-03-21 06:12 - 2013-01-30 05:49 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-03-20 22:23 - 2013-02-06 02:07 - 00000000 ____D () C:\Temp
2015-03-20 19:34 - 2014-05-04 18:34 - 00000000 ____D () C:\Program Files\WhoCrashed
2015-03-20 18:06 - 2013-02-01 15:18 - 00000000 ____D () C:\Program Files\Vuze
2015-03-19 07:56 - 2013-01-29 23:12 - 00000000 ____D () C:\Windows\pss
2015-03-19 06:48 - 2013-03-25 17:56 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\NPE
2015-03-19 02:39 - 2013-03-04 20:10 - 00000000 ____D () C:\Program Files\KaloMa
2015-03-19 00:48 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\System32\LogFiles
2015-03-19 00:26 - 2014-06-16 02:02 - 00064681 ____H () C:\Windows\System32\BTImages.dat
2015-03-19 00:25 - 2013-01-25 15:30 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-03-19 00:21 - 2013-02-04 05:24 - 00000000 ____D () C:\Program Files\USB Deview
2015-03-19 00:20 - 2014-09-14 21:01 - 00000000 ____D () C:\Program Files\Bluescreen View
2015-03-19 00:20 - 2014-02-14 02:24 - 00000000 ____D () C:\Program Files\DriverView v1.45
2015-03-18 22:11 - 2013-07-16 15:55 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\FileZilla
2015-03-18 21:27 - 2014-02-24 06:30 - 00000000 ____D () C:\Users\Friedrich\.VirtualBox
2015-03-18 21:17 - 2013-01-25 15:37 - 00000000 ___HD () C:\Program Files\Temp
2015-03-18 21:04 - 2013-02-01 15:18 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Azureus
2015-03-18 18:45 - 2013-02-17 08:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\VMware
2015-03-18 18:45 - 2013-02-17 08:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\VMware
2015-03-16 21:48 - 2013-01-30 01:16 - 00000000 ____D () C:\Users\Friedrich\Mädels u. Chatter
2015-03-16 14:56 - 2015-02-09 11:04 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\.Tribler
2015-03-15 13:50 - 2013-01-31 03:07 - 00000000 ____D () C:\Program Files\Trillian
2015-03-14 17:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2015-03-12 16:44 - 2014-08-17 15:52 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Adobe
2015-03-12 16:44 - 2013-01-29 22:44 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2015-03-12 16:44 - 2013-01-29 22:44 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2015-03-12 15:27 - 2013-02-01 15:44 - 00000000 ____D () C:\Program Files\Search Everything
2015-03-12 15:24 - 2013-03-19 12:11 - 00000000 ____D () C:\Windows\System32\MAGIX
2015-03-12 01:23 - 2013-02-01 16:32 - 00000000 ____D () C:\ProgramData\Origin
2015-03-11 20:42 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\System32\de-DE
2015-03-11 20:32 - 2014-02-19 19:09 - 00000000 ___RD () C:\Users\Friedrich\Virtual Machines
2015-03-11 20:17 - 2013-08-03 23:48 - 00000000 ____D () C:\Windows\System32\MRT
2015-03-11 15:19 - 2013-01-29 22:28 - 00007655 _____ () C:\Users\Friedrich\AppData\Local\Resmon.ResmonCfg
2015-03-11 13:36 - 2014-07-24 00:39 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\.minecraft
2015-03-11 13:26 - 2013-02-07 04:13 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Razer
2015-03-11 13:26 - 2013-02-07 04:12 - 00000000 ____D () C:\ProgramData\Razer
2015-03-11 13:26 - 2013-01-30 05:03 - 00000000 ____D () C:\Program Files\Razer
2015-03-11 12:11 - 2013-08-21 03:42 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\midori
2015-03-11 02:35 - 2013-02-06 02:14 - 00000000 ____D () C:\ProgramData\TEMP
2015-03-10 04:18 - 2014-06-24 16:21 - 00000000 ____D () C:\Program Files\SRWare Iron
2015-03-09 09:57 - 2013-04-11 01:04 - 00000000 ____D () C:\Program Files\SpeedFan
2015-03-09 08:08 - 2014-08-23 16:30 - 00000000 ____D () C:\Users\Friedrich\Desktop\New Handy Root und ähnliches Tutorials
2015-03-08 10:56 - 2013-07-16 15:55 - 00000000 ____D () C:\Program Files\FileZilla FTP Client
2015-03-08 04:48 - 2014-01-22 17:33 - 00000000 ____D () C:\Users\Friedrich\.dbus-keyrings
2015-03-08 04:25 - 2014-07-15 21:51 - 00000000 ____D () C:\Program Files\GameforgeLive
2015-03-08 02:35 - 2013-11-19 10:19 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Warner Bros. Interactive Entertainment
2015-03-06 05:11 - 2013-02-14 06:50 - 00000000 ____D () C:\Program Files\QuickTime
2015-03-06 04:28 - 2013-09-19 21:42 - 00000000 ____D () C:\ProgramData\Oracle
2015-03-06 04:25 - 2014-01-15 06:51 - 00096680 _____ (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2015-03-06 04:25 - 2013-03-05 05:07 - 00000000 ____D () C:\Program Files\Java
2015-03-05 08:01 - 2013-08-13 00:14 - 00000000 ____D () C:\Users\Friedrich\Documents\3DMark
2015-03-05 07:58 - 2014-06-16 05:52 - 00000022 _____ () C:\Windows\GPU-Z.INI
2015-03-05 05:28 - 2013-02-05 07:26 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2015-03-05 05:11 - 2013-02-07 01:16 - 00000000 ____D () C:\Westwood
2015-03-05 03:01 - 2014-04-11 03:10 - 00000000 ____D () C:\Program Files\prime95 v279
2015-03-05 02:40 - 2015-02-11 15:43 - 00000000 ____D () C:\Users\Friedrich\Desktop\Spionaufnahmen mit LifeCam
2015-03-05 02:18 - 2015-02-12 12:20 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\GetRight
2015-03-04 05:16 - 2014-03-11 20:56 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\MPC-HC
2015-03-04 01:56 - 2013-02-01 16:32 - 00000000 ____D () C:\Program Files\Origin
2015-03-04 00:57 - 2013-07-24 22:30 - 00000000 ____D () C:\HammerAutosave
2015-03-03 18:13 - 2013-11-22 18:50 - 00000000 ____D () C:\Program Files\AIMP3
2015-03-02 18:21 - 2013-01-30 02:15 - 00000000 ____D () C:\Users\Friedrich\Desktop\Ernährung u Sportinfos zusatz zur MAPPE
2015-03-02 02:15 - 2013-02-26 18:36 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Audacity
2015-03-02 02:11 - 2013-02-26 18:36 - 00000000 ____D () C:\Program Files\Audacity
2015-03-01 23:47 - 2015-02-12 12:21 - 00000000 ____D () C:\ProgramData\GetRight
2015-02-28 19:33 - 2013-02-03 00:02 - 02712576 _____ () C:\Users\Friedrich\AppData\Local\file__0.localstorage
2015-02-28 17:10 - 2013-05-10 04:41 - 00000000 ____D () C:\Program Files\IsoBuster
2015-02-27 17:38 - 2013-01-30 01:44 - 00000000 ____D () C:\Users\Friedrich\Desktop\Canon Shots
2015-02-27 16:52 - 2013-02-01 16:51 - 00000000 ____D () C:\Program Files\Futuremark
2015-02-27 03:26 - 2013-02-26 18:48 - 00000000 ____D () C:\Users\Public\Documents\Lightworks
2015-02-27 03:20 - 2013-02-26 18:48 - 00000000 ____D () C:\Program Files\Lightworks
2015-02-26 21:20 - 2011-04-28 16:10 - 119837696 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2015-02-25 03:10 - 2014-06-28 07:22 - 00000000 ____D () C:\Users\Friedrich\Documents\EthanMeteorHunterDemo
2015-02-25 01:15 - 2013-01-30 01:16 - 00000000 ____D () C:\Users\Friedrich\Martin Krüger
2015-02-25 01:14 - 2013-05-24 01:11 - 00000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe PNG Format CS5 Prefs

Files to move or delete:
====================
C:\Users\Friedrich\Bsb.exe
C:\Users\Friedrich\cc_20140124_180349.reg
C:\Users\Friedrich\cc_20140315_160443.reg
C:\Users\Friedrich\cc_20140718_151624.reg
C:\Users\Friedrich\cc_20140905_190648.reg
C:\Users\Friedrich\cc_20141008_060204.reg
C:\Users\Friedrich\IP_Log_Data.js
C:\Users\Friedrich\regsicherung.reg
C:\Users\Friedrich\Sicherung reg von CCleaner 2.reg


==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points  =========================

Restore point made on: 2015-03-25 07:50:04

==================== Memory info ===========================

Percentage of memory in use: 7%
Total physical RAM: 8141.82 MB
Available physical RAM: 7510.87 MB
Total Pagefile: 8140.11 MB
Available Pagefile: 7523 MB
Total Virtual: 2047.88 MB
Available Virtual: 1943.28 MB

==================== Drives ================================

Drive c: (Lokaler Datenträger) (Fixed) (Total:2048 GB) (Free:89.2 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Backup Datenträger RED 3TB) (Fixed) (Total:2048 GB) (Free:327.4 GB) NTFS
Drive e: (Medien Datenträger) (Fixed) (Total:1863.01 GB) (Free:332.27 GB) NTFS
Drive f: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive g: (64bitGaming) (Fixed) (Total:1862.92 GB) (Free:1543.44 GB) NTFS
Drive h: (GSP1RMCPRFRER_DE_DVD) (CDROM) (Total:2.34 GB) (Free:0 GB) UDF
Drive i: () (Removable) (Total:0.93 GB) (Free:0.93 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 379CF46E)
Partition 1: (Active) - (Size=2048 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 02962212)
Partition 1: (Not Active) - (Size=2048 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 1863 GB) (Disk ID: 03AA03A9)
Partition 1: (Active) - (Size=1863 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 0FD998DB)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1862.9 GB) - (Type=07 NTFS)

========================================================
Disk: 4 (Size: 960 MB) (Disk ID: 004E1FE0)
Partition 1: (Active) - (Size=960 MB) - (Type=0B)


LastRegBack: 2015-03-26 07:00

==================== End Of Log ============================

--- --- ---

schrauber 27.03.2015 15:58

Mach bitte noch folgendes, im normalen Modus:

CMD öffnen, schreibe:

bitsadmin /list /verbose > c:\bitsadmin.txt

Poste bitte den Inhalt der bitsadmin.txt.

Friedrich_ 27.03.2015 17:28

re7
 
Code:

BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Listed 0 job(s).


schrauber 28.03.2015 03:21

Mysteriös.....

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Friedrich_ 28.03.2015 14:54

re8
 
Malwarebytes Anti Rootkit-LOG
Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2015.03.28.03

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.17691
Friedrich :: DSLSERVICE [administrator]

28.03.2015 13:54:09
mbar-log-2015-03-28 (13-54-09).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged.
Objects scanned: 454661
Time elapsed: 52 minute(s), 40 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 4
Physical Sector #5860513168 on Drive #0 (Forged physical sector) -> No action taken.
Physical Sector #5860515472 on Drive #0 (Forged physical sector) -> No action taken.
Physical Sector #5860515508 on Drive #0 (Forged physical sector) -> No action taken.
Physical Sector #5860515544 on Drive #0 (Forged physical sector) -> No action taken.

(end)

Die forget sectors hab ich jetzt mal sicherheitshalber nicht entfernt.

Friedrich_ 28.03.2015 14:55

re7.2
 
TDSKiller-Log: Teil 1
Code:

13:50:20.0456 0x1398  TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
13:50:24.0138 0x1398  ============================================================
13:50:24.0138 0x1398  Current date / time: 2015/03/28 13:50:24.0138
13:50:24.0138 0x1398  SystemInfo:
13:50:24.0138 0x1398 
13:50:24.0138 0x1398  OS Version: 6.1.7601 ServicePack: 1.0
13:50:24.0138 0x1398  Product type: Workstation
13:50:24.0138 0x1398  ComputerName: DSLSERVICE
13:50:24.0138 0x1398  UserName: Friedrich
13:50:24.0138 0x1398  Windows directory: C:\Windows
13:50:24.0138 0x1398  System windows directory: C:\Windows
13:50:24.0138 0x1398  Processor architecture: Intel x86
13:50:24.0138 0x1398  Number of processors: 8
13:50:24.0138 0x1398  Page size: 0x1000
13:50:24.0138 0x1398  Boot type: Normal boot
13:50:24.0138 0x1398  ============================================================
13:50:27.0866 0x1398  KLMD registered as C:\Windows\system32\drivers\20223527.sys
13:50:28.0584 0x1398  System UUID: {9E6F4451-54DE-6927-49D6-BB4865D7A155}
13:50:29.0098 0x1398  Drive \Device\Harddisk0\DR0 - Size: 0x2BAA1476000 ( 2794.52 Gb ), SectorSize: 0x200, Cylinders: 0x59101, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:50:29.0114 0x1398  Drive \Device\Harddisk1\DR1 - Size: 0x2BAA1476000 ( 2794.52 Gb ), SectorSize: 0x200, Cylinders: 0x59101, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:50:29.0114 0x1398  Drive \Device\Harddisk3\DR3 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:50:29.0114 0x1398  Drive \Device\Harddisk2\DR2 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:50:29.0114 0x1398  ============================================================
13:50:29.0114 0x1398  \Device\Harddisk0\DR0:
13:50:29.0114 0x1398  MBR partitions:
13:50:29.0114 0x1398  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xFFFFF800
13:50:29.0114 0x1398  \Device\Harddisk1\DR1:
13:50:29.0114 0x1398  MBR partitions:
13:50:29.0114 0x1398  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xFFFFF800
13:50:29.0114 0x1398  \Device\Harddisk3\DR3:
13:50:29.0114 0x1398  MBR partitions:
13:50:29.0114 0x1398  \Device\Harddisk3\DR3\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xE8E035C1
13:50:29.0114 0x1398  \Device\Harddisk2\DR2:
13:50:29.0114 0x1398  MBR partitions:
13:50:29.0114 0x1398  \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
13:50:29.0114 0x1398  \Device\Harddisk2\DR2\Partition2: MBR, Type 0x7, StartLBA 0x33000, BlocksNum 0xE8DD5000
13:50:29.0114 0x1398  ============================================================
13:50:29.0145 0x1398  C: <-> \Device\Harddisk1\DR1\Partition1
13:50:29.0644 0x1398  D: <-> \Device\Harddisk3\DR3\Partition1
13:50:29.0660 0x1398  F: <-> \Device\Harddisk0\DR0\Partition1
13:50:29.0676 0x1398  H: <-> \Device\Harddisk2\DR2\Partition1
13:50:29.0691 0x1398  I: <-> \Device\Harddisk2\DR2\Partition2
13:50:29.0691 0x1398  ============================================================
13:50:29.0691 0x1398  Initialize success
13:50:29.0691 0x1398  ============================================================
13:51:30.0447 0x1468  ============================================================
13:51:30.0447 0x1468  Scan started
13:51:30.0447 0x1468  Mode: Manual; SigCheck; TDLFS;
13:51:30.0447 0x1468  ============================================================
13:51:30.0447 0x1468  KSN ping started
13:51:30.0993 0x1468  KSN ping finished: true
13:51:31.0773 0x1468  ================ Scan system memory ========================
13:51:31.0773 0x1468  System memory - ok
13:51:31.0773 0x1468  ================ Scan services =============================
13:51:31.0929 0x1468  [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
13:51:32.0054 0x1468  1394ohci - ok
13:51:32.0132 0x1468  [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI            C:\Windows\system32\drivers\ACPI.sys
13:51:32.0147 0x1468  ACPI - ok
13:51:32.0194 0x1468  [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
13:51:32.0241 0x1468  AcpiPmi - ok
13:51:32.0303 0x1468  [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
13:51:32.0319 0x1468  adp94xx - ok
13:51:32.0350 0x1468  [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci        C:\Windows\system32\drivers\adpahci.sys
13:51:32.0350 0x1468  adpahci - ok
13:51:32.0412 0x1468  [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320        C:\Windows\system32\drivers\adpu320.sys
13:51:32.0428 0x1468  adpu320 - ok
13:51:32.0459 0x1468  [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
13:51:32.0553 0x1468  AeLookupSvc - ok
13:51:32.0646 0x1468  [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD            C:\Windows\system32\drivers\afd.sys
13:51:32.0709 0x1468  AFD - ok
13:51:32.0771 0x1468  [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440          C:\Windows\system32\drivers\agp440.sys
13:51:32.0787 0x1468  agp440 - ok
13:51:32.0834 0x1468  [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
13:51:32.0849 0x1468  aic78xx - ok
13:51:32.0896 0x1468  [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG            C:\Windows\System32\alg.exe
13:51:32.0927 0x1468  ALG - ok
13:51:32.0990 0x1468  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide          C:\Windows\system32\drivers\aliide.sys
13:51:33.0005 0x1468  aliide - ok
13:51:33.0021 0x1468  [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
13:51:33.0036 0x1468  amdagp - ok
13:51:33.0083 0x1468  [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide          C:\Windows\system32\drivers\amdide.sys
13:51:33.0083 0x1468  amdide - ok
13:51:33.0130 0x1468  [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
13:51:33.0161 0x1468  AmdK8 - ok
13:51:33.0208 0x1468  [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
13:51:33.0239 0x1468  AmdPPM - ok
13:51:33.0286 0x1468  [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
13:51:33.0302 0x1468  amdsata - ok
13:51:33.0364 0x1468  [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
13:51:33.0380 0x1468  amdsbs - ok
13:51:33.0395 0x1468  [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
13:51:33.0395 0x1468  amdxata - ok
13:51:33.0458 0x1468  [ AEA177F783E20150ACE5383EE368DA19, 8FA9EE27AA1F22E8B8FE33A21028CA1E0062BAA95CB132C20D55B98C03B4254F ] AppID          C:\Windows\system32\drivers\appid.sys
13:51:33.0489 0x1468  AppID - ok
13:51:33.0551 0x1468  [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D628B32D00F2B66765E6B97E4B ] AppIDSvc        C:\Windows\System32\appidsvc.dll
13:51:33.0582 0x1468  AppIDSvc - ok
13:51:33.0645 0x1468  [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo        C:\Windows\System32\appinfo.dll
13:51:33.0676 0x1468  Appinfo - ok
13:51:33.0738 0x1468  [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt        C:\Windows\System32\appmgmts.dll
13:51:33.0754 0x1468  AppMgmt - ok
13:51:33.0816 0x1468  [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc            C:\Windows\system32\drivers\arc.sys
13:51:33.0832 0x1468  arc - ok
13:51:33.0863 0x1468  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas          C:\Windows\system32\drivers\arcsas.sys
13:51:33.0879 0x1468  arcsas - ok
13:51:34.0019 0x1468  [ 537B2948976F5D9B5767B74A63EBB395, 1A14F8B582E74AD15B612EDA5B707AA3CB0B2A107ED14572B4232EAA7383B634 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
13:51:34.0128 0x1468  aspnet_state - ok
13:51:34.0175 0x1468  [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
13:51:34.0394 0x1468  AsyncMac - ok
13:51:34.0409 0x1468  [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi          C:\Windows\system32\drivers\atapi.sys
13:51:34.0425 0x1468  atapi - ok
13:51:34.0487 0x1468  [ F4157B3CECF19B1C266C83AFF051C97A, 26728B59B6003EB36BC322D189254574E94790CE23637228A669FAD6ED76ECE3 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:51:34.0550 0x1468  AudioEndpointBuilder - ok
13:51:34.0565 0x1468  [ F4157B3CECF19B1C266C83AFF051C97A, 26728B59B6003EB36BC322D189254574E94790CE23637228A669FAD6ED76ECE3 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
13:51:34.0581 0x1468  Audiosrv - ok
13:51:34.0643 0x1468  [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV        C:\Windows\System32\AxInstSV.dll
13:51:34.0690 0x1468  AxInstSV - ok
13:51:34.0768 0x1468  [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv        C:\Windows\system32\drivers\bxvbdx.sys
13:51:34.0799 0x1468  b06bdrv - ok
13:51:34.0846 0x1468  [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
13:51:34.0893 0x1468  b57nd60x - ok
13:51:34.0955 0x1468  [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC          C:\Windows\System32\bdesvc.dll
13:51:34.0986 0x1468  BDESVC - ok
13:51:35.0033 0x1468  [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep            C:\Windows\system32\drivers\Beep.sys
13:51:35.0064 0x1468  Beep - ok
13:51:35.0127 0x1468  [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE            C:\Windows\System32\bfe.dll
13:51:35.0142 0x1468  BFE - ok
13:51:35.0174 0x1468  [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS            C:\Windows\System32\qmgr.dll
13:51:35.0205 0x1468  BITS - ok
13:51:35.0220 0x1468  [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
13:51:35.0236 0x1468  blbdrive - ok
13:51:35.0283 0x1468  [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
13:51:35.0330 0x1468  bowser - ok
13:51:35.0330 0x1468  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
13:51:35.0361 0x1468  BrFiltLo - ok
13:51:35.0361 0x1468  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
13:51:35.0377 0x1468  BrFiltUp - ok
13:51:35.0470 0x1468  [ 77361D72A04F18809D0EFB6CCEB74D4B, 55E7DB65BB29FF421F138CDFF05E5ECFFC7C8862FAA68F6179A3BA9D6B69AE64 ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
13:51:35.0517 0x1468  BridgeMP - ok
13:51:35.0533 0x1468  [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser        C:\Windows\System32\browser.dll
13:51:35.0548 0x1468  Browser - ok
13:51:35.0564 0x1468  [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
13:51:35.0579 0x1468  Brserid - ok
13:51:35.0595 0x1468  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
13:51:35.0611 0x1468  BrSerWdm - ok
13:51:35.0673 0x1468  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
13:51:35.0704 0x1468  BrUsbMdm - ok
13:51:35.0704 0x1468  [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
13:51:35.0751 0x1468  BrUsbSer - ok
13:51:35.0751 0x1468  [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
13:51:35.0782 0x1468  BTHMODEM - ok
13:51:35.0829 0x1468  [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv        C:\Windows\system32\bthserv.dll
13:51:35.0860 0x1468  bthserv - ok
13:51:36.0079 0x1468  catchme - ok
13:51:36.0172 0x1468  [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
13:51:36.0219 0x1468  cdfs - ok
13:51:36.0297 0x1468  [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
13:51:36.0328 0x1468  cdrom - ok
13:51:36.0375 0x1468  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc    C:\Windows\System32\certprop.dll
13:51:36.0422 0x1468  CertPropSvc - ok
13:51:36.0422 0x1468  [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass        C:\Windows\system32\drivers\circlass.sys
13:51:36.0453 0x1468  circlass - ok
13:51:36.0562 0x1468  [ DBC8CDAFC84E96E894C3BAAED9B30F47, A25CDF4BBF8227878D3CBB8E74904A43751EC4E98DFEBFE4CBD3953890A170F9 ] cleanhlp        C:\EEK\bin\cleanhlp32.sys
13:51:36.0625 0x1468  cleanhlp - ok
13:51:36.0656 0x1468  [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F9785BD66C0C1E03A0F1C223A26A ] CLFS            C:\Windows\system32\CLFS.sys
13:51:36.0671 0x1468  CLFS - ok
13:51:36.0812 0x1468  [ 4AA6694FB767BBFF6A8EF080806447BD, 4920B3683FDE19A86453C76E08C23132B037D254AFB7147E84130C06AA90B0F8 ] CLHNServiceForPowerDVD C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
13:51:36.0827 0x1468  CLHNServiceForPowerDVD - ok
13:51:36.0952 0x1468  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:51:36.0968 0x1468  clr_optimization_v2.0.50727_32 - ok
13:51:37.0046 0x1468  [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:51:37.0155 0x1468  clr_optimization_v4.0.30319_32 - ok
13:51:37.0186 0x1468  [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
13:51:37.0217 0x1468  CmBatt - ok
13:51:37.0264 0x1468  [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
13:51:37.0264 0x1468  cmdide - ok
13:51:37.0327 0x1468  [ 3051724F223EA48968B19567DE2A81F4, DCC27DE1B2B35866FC6DBDE95A368E7D0D346B6C3F31D0BACA63DD39B0A8874E ] CNG            C:\Windows\system32\Drivers\cng.sys
13:51:37.0358 0x1468  CNG - ok
13:51:37.0405 0x1468  [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
13:51:37.0420 0x1468  Compbatt - ok
13:51:37.0483 0x1468  [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
13:51:37.0514 0x1468  CompositeBus - ok
13:51:37.0529 0x1468  COMSysApp - ok
13:51:37.0561 0x1468  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
13:51:37.0576 0x1468  crcdisk - ok
13:51:37.0654 0x1468  [ 7CA1BECEA5DE2643ADDAD32670E7A4C9, E3AB4CC52A97E3855D7EAB87363F807FDD2162ED8C76A036CD71549ED64E7797 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
13:51:37.0685 0x1468  CryptSvc - ok
13:51:37.0795 0x1468  [ F054744F67576A01139885173392502B, 4FEA15AABC4FC63A3E991412CAF17283BBD257172EF7E255F40F5E22E0286902 ] CrystalSysInfo  C:\Program Files\MediaCoder\SysInfo.sys
13:51:37.0810 0x1468  CrystalSysInfo - ok
13:51:37.0841 0x1468  [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] CSC            C:\Windows\system32\drivers\csc.sys
13:51:37.0888 0x1468  CSC - ok
13:51:37.0935 0x1468  [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B09F062295699131232712B558 ] CscService      C:\Windows\System32\cscsvc.dll
13:51:37.0982 0x1468  CscService - ok
13:51:38.0075 0x1468  [ D3484412EAE43685E3AD304C9979F30E, 0F45C056C3E2FE541FF2BD3914CDC823CF4048A57B967E07B95DFF673E968F35 ] CyberLink PowerDVD 11.0 Monitor Service C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
13:51:38.0091 0x1468  CyberLink PowerDVD 11.0 Monitor Service - ok
13:51:38.0122 0x1468  [ 4B0F03AF88FF89441EF57175849C3961, E758730704E52C7D2F8D061B6D40788D3F92F490A5A2F9F01E71C3CD959CA6E7 ] CyberLink PowerDVD 11.0 Service C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
13:51:38.0153 0x1468  CyberLink PowerDVD 11.0 Service - ok
13:51:38.0200 0x1468  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch      C:\Windows\system32\rpcss.dll
13:51:38.0263 0x1468  DcomLaunch - ok
13:51:38.0278 0x1468  [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc      C:\Windows\System32\defragsvc.dll
13:51:38.0309 0x1468  defragsvc - ok
13:51:38.0356 0x1468  [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
13:51:38.0403 0x1468  DfsC - ok
13:51:38.0465 0x1468  [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp            C:\Windows\system32\dhcpcore.dll
13:51:38.0497 0x1468  Dhcp - ok
13:51:38.0512 0x1468  [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache        C:\Windows\system32\drivers\discache.sys
13:51:38.0543 0x1468  discache - ok
13:51:38.0590 0x1468  [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk            C:\Windows\system32\drivers\disk.sys
13:51:38.0606 0x1468  Disk - ok
13:51:38.0621 0x1468  [ 2A958EF85DB1B61FFCA65044FA4BCE9E, C83511685EE1CE85A5ADF9B5BE96C375A521601F66024BDC3EE044C0B6E85D69 ] dmvsc          C:\Windows\system32\drivers\dmvsc.sys
13:51:38.0653 0x1468  dmvsc - ok
13:51:38.0699 0x1468  [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache        C:\Windows\System32\dnsrslvr.dll
13:51:38.0715 0x1468  Dnscache - ok
13:51:38.0809 0x1468  [ E230157E4B157E0B8D03C342B71E5884, DF5E8956CE7679F1E47FE4ECC1BB2CE4A3F3333CF69C6B5B0EA2670E34A0F163 ] Dokan          C:\Windows\system32\drivers\dokan.sys
13:51:38.0824 0x1468  Dokan - ok
13:51:38.0933 0x1468  [ 85F6D1DAE0963121A54BD9C2278B1430, 2A159FB218745C279C0335CD96E506B2C7F2C9312D977AC340E3A212FC347413 ] DokanMounter    C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe
13:51:38.0949 0x1468  DokanMounter - ok
13:51:38.0996 0x1468  [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc        C:\Windows\System32\dot3svc.dll
13:51:39.0043 0x1468  dot3svc - ok
13:51:39.0105 0x1468  [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS            C:\Windows\system32\dps.dll
13:51:39.0152 0x1468  DPS - ok
13:51:39.0230 0x1468  [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
13:51:39.0261 0x1468  drmkaud - ok
13:51:39.0339 0x1468  [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
13:51:39.0355 0x1468  DXGKrnl - ok
13:51:39.0417 0x1468  [ 22EF8965101685ADD128F03A2B03CE16, 677F7B32C7A45C26F2F0DB67FFB526E9742E4B3A8BEAEA7B814CBCA2F56D6D5A ] E1G60          C:\Windows\system32\DRIVERS\E1G60I32.sys
13:51:39.0433 0x1468  E1G60 - ok
13:51:39.0495 0x1468  [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost        C:\Windows\System32\eapsvc.dll
13:51:39.0526 0x1468  EapHost - ok
13:51:39.0635 0x1468  [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv          C:\Windows\system32\drivers\evbdx.sys
13:51:39.0698 0x1468  ebdrv - ok
13:51:39.0729 0x1468  [ F65F365AC0D1657917EFDB52445C848B, 1BDCEFED2799B5507B28B4D72D13D2DD7A1102B21F3938E98BA65737985A4ED9 ] EFS            C:\Windows\System32\lsass.exe
13:51:39.0745 0x1468  EFS - ok
13:51:39.0854 0x1468  [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
13:51:39.0885 0x1468  ehRecvr - ok
13:51:39.0901 0x1468  [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched        C:\Windows\ehome\ehsched.exe
13:51:39.0916 0x1468  ehSched - ok
13:51:39.0932 0x1468  [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
13:51:39.0947 0x1468  elxstor - ok
13:51:40.0010 0x1468  [ B4BA0736D3D2736E3862697776866986, 21C6853BE16A7948D1A24558F77815DCBE5484387EDBEF6010B553E62883A4D9 ] EMET_Service    C:\Program Files\EMET 5.1\EMET_Service.exe
13:51:40.0025 0x1468  EMET_Service - ok
13:51:40.0103 0x1468  [ FD9FC82F134B1C91004FFC76A5AE494B, 76CF65ED91D4719CD5620479E492259224715FC67E3CD9AA11E5DD0D7FB65A45 ] ENTECH          C:\Windows\system32\DRIVERS\ENTECH.sys
13:51:40.0103 0x1468  ENTECH - detected UnsignedFile.Multi.Generic ( 1 )
13:51:40.0696 0x1468  Detect skipped due to KSN trusted
13:51:40.0696 0x1468  ENTECH - ok
13:51:40.0727 0x1468  [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
13:51:40.0759 0x1468  ErrDev - ok
13:51:40.0821 0x1468  [ 24E564F710D887ECC75CFE59882ECC5D, 286B74C272E71AB2C64796790BC3425D3C29AA92B1018F77F7022B56DE9BA168 ] es1371          C:\Windows\system32\drivers\es1371mp.sys
13:51:40.0837 0x1468  es1371 - ok
13:51:40.0899 0x1468  [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem    C:\Windows\system32\es.dll
13:51:40.0961 0x1468  EventSystem - ok
13:51:40.0977 0x1468  [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat          C:\Windows\system32\drivers\exfat.sys
13:51:41.0008 0x1468  exfat - ok
13:51:41.0024 0x1468  [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
13:51:41.0055 0x1468  fastfat - ok
13:51:41.0102 0x1468  [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax            C:\Windows\system32\fxssvc.exe
13:51:41.0133 0x1468  Fax - ok
13:51:41.0180 0x1468  [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc            C:\Windows\system32\drivers\fdc.sys
13:51:41.0195 0x1468  fdc - ok
13:51:41.0242 0x1468  [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost        C:\Windows\system32\fdPHost.dll
13:51:41.0273 0x1468  fdPHost - ok
13:51:41.0289 0x1468  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub        C:\Windows\system32\fdrespub.dll
13:51:41.0305 0x1468  FDResPub - ok
13:51:41.0305 0x1468  [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
13:51:41.0320 0x1468  FileInfo - ok
13:51:41.0336 0x1468  [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
13:51:41.0351 0x1468  Filetrace - ok
13:51:41.0351 0x1468  [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
13:51:41.0367 0x1468  flpydisk - ok
13:51:41.0383 0x1468  [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
13:51:41.0398 0x1468  FltMgr - ok
13:51:41.0492 0x1468  [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] FontCache      C:\Windows\system32\FntCache.dll
13:51:41.0554 0x1468  FontCache - ok
13:51:41.0632 0x1468  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:51:41.0648 0x1468  FontCache3.0.0.0 - ok
13:51:41.0648 0x1468  [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
13:51:41.0663 0x1468  FsDepends - ok
13:51:41.0679 0x1468  [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
13:51:41.0679 0x1468  Fs_Rec - ok
13:51:41.0835 0x1468  [ 49CAD71044454C45A875F04F84935227, 3F75C67E516E42BD5C5C357B7A9177BCCA64534344EC566E29A2D5911B5495BD ] Futuremark SystemInfo Service C:\Program Files\Futuremark\SystemInfo\FMSISvc.exe
13:51:41.0866 0x1468  Futuremark SystemInfo Service - ok
13:51:41.0913 0x1468  [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
13:51:41.0929 0x1468  fvevol - ok
13:51:41.0975 0x1468  [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
13:51:41.0991 0x1468  gagp30kx - ok
13:51:42.0053 0x1468  [ 77EBF3E9386DAA51551AF429052D88D0, 94C3294BB9E14B07448734AE65B37801D3FF15BEC987D182A929A017FEF7B276 ] giveio          C:\Windows\system32\giveio.sys
13:51:42.0069 0x1468  giveio - detected UnsignedFile.Multi.Generic ( 1 )
13:51:42.0677 0x1468  Detect skipped due to KSN trusted
13:51:42.0677 0x1468  giveio - ok
13:51:42.0740 0x1468  [ 2B861A88AE8E95C0FC5E11127222AC7B, CD6169B862ABEE9FB4494F92FD3B8CB18ECECFB9355D6A6299B17CF35A32FBE1 ] GKBFltr        C:\Windows\system32\Drivers\GameKB.sys
13:51:42.0771 0x1468  GKBFltr - ok
13:51:42.0833 0x1468  [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc          C:\Windows\System32\gpsvc.dll
13:51:42.0865 0x1468  gpsvc - ok
13:51:42.0927 0x1468  [ 833051C6C6C42117191935F734CFBD97, 5EB5672ABC7994A4AFF855A572158B8BE4FC6E541CFD4B9BE4FF2739A9A6AFB8 ] hamachi        C:\Windows\system32\DRIVERS\hamachi.sys
13:51:42.0943 0x1468  hamachi - ok
13:51:43.0036 0x1468  [ 3F40FA664309ED1CCC3592636A94DDF4, D241BD7FA97F1DA8E7A781535CCBF004D15DCABA7EFDC09EA97D5E549D85B41A ] hcmon          C:\Windows\system32\drivers\hcmon.sys
13:51:43.0052 0x1468  hcmon - ok
13:51:43.0083 0x1468  [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
13:51:43.0114 0x1468  hcw85cir - ok
13:51:43.0177 0x1468  [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:51:43.0223 0x1468  HdAudAddService - ok
13:51:43.0270 0x1468  [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
13:51:43.0286 0x1468  HDAudBus - ok
13:51:43.0364 0x1468  [ 4598E747284210CCC572FC304D0C687F, 6B3D2560B4F6951B613FADCB1449A189F7065070061D3C45DC77BA6E2DC5D523 ] HH10Help.sys    C:\Windows\system32\drivers\HH10Help.sys
13:51:43.0379 0x1468  HH10Help.sys - detected UnsignedFile.Multi.Generic ( 1 )
13:51:43.0972 0x1468  Detect skipped due to KSN trusted
13:51:43.0972 0x1468  HH10Help.sys - ok
13:51:44.0003 0x1468  [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt        C:\Windows\system32\drivers\HidBatt.sys
13:51:44.0035 0x1468  HidBatt - ok
13:51:44.0050 0x1468  [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth          C:\Windows\system32\drivers\hidbth.sys
13:51:44.0081 0x1468  HidBth - ok
13:51:44.0097 0x1468  [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr          C:\Windows\system32\drivers\hidir.sys
13:51:44.0128 0x1468  HidIr - ok
13:51:44.0159 0x1468  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv        C:\Windows\System32\hidserv.dll
13:51:44.0191 0x1468  hidserv - ok
13:51:44.0253 0x1468  [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
13:51:44.0300 0x1468  HidUsb - ok
13:51:44.0362 0x1468  [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc          C:\Windows\system32\kmsvc.dll
13:51:44.0378 0x1468  hkmsvc - ok
13:51:44.0393 0x1468  [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
13:51:44.0409 0x1468  HomeGroupListener - ok
13:51:44.0471 0x1468  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
13:51:44.0487 0x1468  HomeGroupProvider - ok
13:51:44.0534 0x1468  [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
13:51:44.0565 0x1468  HpSAMD - ok
13:51:44.0596 0x1468  [ 871917B07A141BFF43D76D8844D48106, 30C702008D0EE57D63F74864967DD19A55A268E77E42B5B3CC73037AD51D2987 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
13:51:44.0627 0x1468  HTTP - ok
13:51:44.0643 0x1468  [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
13:51:44.0643 0x1468  hwpolicy - ok
13:51:44.0705 0x1468  [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
13:51:44.0737 0x1468  i8042prt - ok
13:51:44.0783 0x1468  [ 70BADD827F0C6863AD7F4850DCC5E79B, 5B062D1552E00FDEBE854141AC8015AA046FC30C7D3417F60185FE75893AAC61 ] iaStorA        C:\Windows\system32\drivers\iaStorA.sys
13:51:44.0815 0x1468  iaStorA - ok
13:51:44.0830 0x1468  [ 48BD3DD357DB6BB61FB2E6EF3D137764, D1ABD42A647A6CC0612E2A1ED5266AA222EC374B6CA33F386B5950F5D38AC021 ] iaStorF        C:\Windows\system32\drivers\iaStorF.sys
13:51:44.0830 0x1468  iaStorF - ok
13:51:44.0877 0x1468  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
13:51:44.0893 0x1468  iaStorV - ok
13:51:44.0971 0x1468  [ 33D4D4A24791587E83F7EE05A446FB7E, 081E48AF76D7D3A71850A4C910EFBB0B280235E2A5303178B0338230F4BA2DE2 ] ICCS            C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
13:51:44.0986 0x1468  ICCS - detected UnsignedFile.Multi.Generic ( 1 )
13:51:45.0579 0x1468  Detect skipped due to KSN trusted
13:51:45.0579 0x1468  ICCS - ok
13:51:45.0719 0x1468  [ B04830C87E64FC233DD8541186163DF3, 8C3B47596D20B95CA5AEBB0D47C2B52B18EB9D220FA693F8F061413FCB41295C ] icsak          C:\Program Files\CheckPoint\AKL\ak\icsak.sys
13:51:45.0735 0x1468  icsak - ok
13:51:45.0813 0x1468  [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT        C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
13:51:45.0829 0x1468  IDriverT - detected UnsignedFile.Multi.Generic ( 1 )
13:51:46.0437 0x1468  Detect skipped due to KSN trusted
13:51:46.0437 0x1468  IDriverT - ok
13:51:46.0531 0x1468  [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc          C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:51:46.0546 0x1468  idsvc - ok
13:51:46.0593 0x1468  IEEtwCollectorService - ok
13:51:46.0671 0x1468  [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp          C:\Windows\system32\drivers\iirsp.sys
13:51:46.0687 0x1468  iirsp - ok
13:51:46.0780 0x1468  [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT          C:\Windows\System32\ikeext.dll
13:51:46.0811 0x1468  IKEEXT - ok
13:51:46.0972 0x1468  [ C93D14ECC955C29CA43CE807CE470754, 2390318A18BEEC8CF625727A1E2A393AC1BD8C00DF1F72FC93939BBD696A8D02 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
13:51:47.0020 0x1468  IntcAzAudAddService - ok
13:51:47.0051 0x1468  [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide        C:\Windows\system32\drivers\intelide.sys
13:51:47.0051 0x1468  intelide - ok
13:51:47.0098 0x1468  [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm        C:\Windows\system32\drivers\intelppm.sys
13:51:47.0113 0x1468  intelppm - ok
13:51:47.0129 0x1468  [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
13:51:47.0160 0x1468  IPBusEnum - ok
13:51:47.0191 0x1468  [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:51:47.0207 0x1468  IpFilterDriver - ok
13:51:47.0238 0x1468  [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
13:51:47.0254 0x1468  iphlpsvc - ok
13:51:47.0269 0x1468  [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
13:51:47.0332 0x1468  IPMIDRV - ok
13:51:47.0332 0x1468  [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
13:51:47.0363 0x1468  IPNAT - ok
13:51:47.0394 0x1468  [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
13:51:47.0410 0x1468  IRENUM - ok
13:51:47.0441 0x1468  [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
13:51:47.0441 0x1468  isapnp - ok
13:51:47.0488 0x1468  [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
13:51:47.0503 0x1468  iScsiPrt - ok
13:51:47.0550 0x1468  [ 4A4DF1763FBE4D148385755D92EC7BA2, 1CB3AB85892248BDA12F73DCC15F9C1484C80B42055E21511F562C189CB0D712 ] ISWKL          C:\Program Files\CheckPoint\AKL\ISWKL.sys
13:51:47.0566 0x1468  ISWKL - ok
13:51:47.0597 0x1468  [ EE6FEC85D7F6F65386B17CD45E1734CA, 887B41F0DB2FFEAEC00B159BF4504F25B4F883C9244EDC193FE3414B390EAB6B ] IswSvc          C:\Program Files\CheckPoint\AKL\AkSVC.exe
13:51:47.0628 0x1468  IswSvc - ok
13:51:47.0706 0x1468  [ C07D93901561622A754E1EEA271960A7, 5846EB3DC5DF35ED2611C61E71BEF1C74E0EF9ADBDA48C17E773A46980CCF6E0 ] iusb3hcs        C:\Windows\system32\drivers\iusb3hcs.sys
13:51:47.0722 0x1468  iusb3hcs - ok
13:51:47.0784 0x1468  [ A352D9B6695F682B7181E5E220FA7D1A, E7CFE5009954873B9196555DAD52EDB09003C25038B60947BD513FBC5CBD02E5 ] iusb3hub        C:\Windows\system32\DRIVERS\iusb3hub.sys
13:51:47.0800 0x1468  iusb3hub - ok
13:51:47.0940 0x1468  [ 68E444FF3D6701891FFF29FF8D44BEEC, 86BAE8F77E33ACA064C4D51211D26DA0F267AC1C340DB31865CE1DBD98FCC5BC ] iusb3xhc        C:\Windows\system32\DRIVERS\iusb3xhc.sys
13:51:47.0971 0x1468  iusb3xhc - ok
13:51:48.0018 0x1468  [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
13:51:48.0034 0x1468  kbdclass - ok
13:51:48.0080 0x1468  [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
13:51:48.0096 0x1468  kbdhid - ok
13:51:48.0112 0x1468  [ F65F365AC0D1657917EFDB52445C848B, 1BDCEFED2799B5507B28B4D72D13D2DD7A1102B21F3938E98BA65737985A4ED9 ] KeyIso          C:\Windows\system32\lsass.exe
13:51:48.0127 0x1468  KeyIso - ok
13:51:48.0190 0x1468  [ 2AD446E7A867C48099227415DD66FB34, 7A5C80C19B870EC2AAB448949758972AD1AE2FD7C158ECF4E17DE54A5982B58A ] KL1            C:\Windows\system32\DRIVERS\kl1.sys
13:51:48.0205 0x1468  KL1 - ok
13:51:48.0314 0x1468  [ CB7B98B51E2DDB6E519EB35DA0E7AFD2, 55C66955192D0D983F9D94C80104D7204103D993D937B140856AF5DB365B4B7D ] KLIF            C:\Windows\system32\DRIVERS\klif.sys
13:51:48.0346 0x1468  KLIF - ok
13:51:48.0424 0x1468  [ 039FB019C92A16A54FE527D93B0CFB96, 080897B377511FD2439EB651086390CD72B822E8222C79AB0569FAFAA14BA0AE ] KLIM6          C:\Windows\system32\DRIVERS\klim6.sys
13:51:48.0439 0x1468  KLIM6 - ok
13:51:48.0502 0x1468  [ 63A2306B751FA5EC31F5CBFE61AF9A26, 4FC200FF4154DDA1122D9CFD67E4192F1A8B60057091E47C924DEEF22BAEA59A ] kltdi          C:\Windows\system32\DRIVERS\kltdi.sys
13:51:48.0517 0x1468  kltdi - ok
13:51:48.0595 0x1468  [ 61A5F5B346EDA29152310B662843277A, FFE560C3623B21AD3B59A1390CF389142C05D7BDA6CCD8178935ACB2F49ACBA0 ] kneps          C:\Windows\system32\DRIVERS\kneps.sys
13:51:48.0611 0x1468  kneps - ok
13:51:48.0658 0x1468  [ 4DAC97CF81FAE4B2988AEF0DF40D04AE, 5560304972693DE5D5B21CE010A76067FA5B64AD5968122EE9F8248B3EA4878E ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
13:51:48.0673 0x1468  KSecDD - ok
13:51:48.0704 0x1468  [ 9EED5E0B7BF784C491C2289A09920BDA, 9E82EB777A01AB32EDA2AE0420546602A82C850D68D2C0AEDB4EA5ADEDF835E6 ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
13:51:48.0720 0x1468  KSecPkg - ok
13:51:48.0751 0x1468  [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm          C:\Windows\system32\msdtckrm.dll
13:51:48.0782 0x1468  KtmRm - ok
13:51:48.0845 0x1468  [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer    C:\Windows\System32\srvsvc.dll
13:51:48.0876 0x1468  LanmanServer - ok
13:51:48.0938 0x1468  [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:51:48.0970 0x1468  LanmanWorkstation - ok
13:51:49.0048 0x1468  [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
13:51:49.0094 0x1468  lltdio - ok
13:51:49.0110 0x1468  [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc        C:\Windows\System32\lltdsvc.dll
13:51:49.0141 0x1468  lltdsvc - ok
13:51:49.0141 0x1468  [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts        C:\Windows\System32\lmhsvc.dll
13:51:49.0172 0x1468  lmhosts - ok
13:51:49.0219 0x1468  [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
13:51:49.0235 0x1468  LSI_FC - ok
13:51:49.0297 0x1468  [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
13:51:49.0313 0x1468  LSI_SAS - ok
13:51:49.0328 0x1468  [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
13:51:49.0344 0x1468  LSI_SAS2 - ok
13:51:49.0360 0x1468  [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
13:51:49.0375 0x1468  LSI_SCSI - ok
13:51:49.0422 0x1468  [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv          C:\Windows\system32\drivers\luafv.sys
13:51:49.0469 0x1468  luafv - ok
13:51:49.0562 0x1468  [ 3B4C137E2CA87CF773204653A80B5BE9, D774945037F7A39EB23392DCCF4B52BDE03134C8D457EB9DDFE761B3B8C3D0D9 ] mbamchameleon  C:\Windows\system32\drivers\mbamchameleon.sys
13:51:49.0578 0x1468  mbamchameleon - ok
13:51:49.0687 0x1468  [ 024ACCA2F972EE094EB0F4289F2FA893, 3C8806DAF521C41C39EFF0065CBA2A85120E78E31F35AC950FB451C59E841782 ] MBAMSwissArmy  C:\Windows\system32\drivers\MBAMSwissArmy.sys
13:51:49.0703 0x1468  MBAMSwissArmy - ok
13:51:49.0734 0x1468  [ 29CB85A1FE091C9D3AA3C72D66DF3E69, FB196EC7F8095752713A336B79835D796F8EA738EE0512386C9116B277A9F210 ] MBfilt          C:\Windows\system32\drivers\MBfilt32.sys
13:51:49.0750 0x1468  MBfilt - ok
13:51:49.0781 0x1468  [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
13:51:49.0796 0x1468  Mcx2Svc - ok
13:51:49.0812 0x1468  [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas        C:\Windows\system32\drivers\megasas.sys
13:51:49.0828 0x1468  megasas - ok
13:51:49.0859 0x1468  [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
13:51:49.0859 0x1468  MegaSR - ok
13:51:49.0937 0x1468  [ 9E0A56C77E9244D2CAAC3811F4B47FCB, 0E70544BBA78DD8E43C5746C064C895A0990373F667A0B6AEA832FBEA2D2B764 ] MEI            C:\Windows\system32\DRIVERS\HECI.sys
13:51:49.0952 0x1468  MEI - ok
13:51:50.0030 0x1468  [ 19D2D9C507D0E7A577807303FE96501B, 0CFBAA935D50AA9939D23597D26A7D8FBAFA85A9267B7DB57E79CDDD8202509A ] mfehidk        C:\Windows\system32\drivers\mfehidk.sys
13:51:50.0062 0x1468  mfehidk - ok
13:51:50.0077 0x1468  [ 6EA4C5591F7EEE370EF4E93ECDD4EFAE, C5961DE45E62399A79412A14C06C1791653D4AD328458BC4CE8D86C298931456 ] mferkdet        C:\Windows\system32\drivers\mferkdet.sys
13:51:50.0093 0x1468  mferkdet - ok
13:51:50.0140 0x1468  [ 0A277C42CBF52C2AF2BAA10B89F2A9AD, 50489A7E43A1B6660074BEDDC8FC60A236658C99895571C7EB6516C873BE2155 ] mfevtp          C:\Windows\system32\mfevtps.exe
13:51:50.0155 0x1468  mfevtp - ok
13:51:50.0264 0x1468  Microsoft SharePoint Workspace Audit Service - ok
13:51:50.0280 0x1468  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS          C:\Windows\system32\mmcss.dll
13:51:50.0327 0x1468  MMCSS - ok
13:51:50.0342 0x1468  [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem          C:\Windows\system32\drivers\modem.sys
13:51:50.0374 0x1468  Modem - ok
13:51:50.0420 0x1468  [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
13:51:50.0452 0x1468  monitor - ok
13:51:50.0514 0x1468  [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
13:51:50.0530 0x1468  mouclass - ok
13:51:50.0576 0x1468  [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
13:51:50.0608 0x1468  mouhid - ok
13:51:50.0654 0x1468  [ FC8771F45ECCCFD89684E38842539B9B, 806DDF2B4830CA866582FE74A521BB7DF26CA0E19013DAF584D3677FB48CC77A ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
13:51:50.0670 0x1468  mountmgr - ok
13:51:50.0779 0x1468  [ 0A68B3E37961CEC327EED518F6D62530, EDEB16545ECDDEA2ADFF73E4DF3E9FD87E4B7126C8CFB037ABAF883D157103DE ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:51:50.0795 0x1468  MozillaMaintenance - ok
13:51:50.0810 0x1468  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio            C:\Windows\system32\drivers\mpio.sys
13:51:50.0826 0x1468  mpio - ok
13:51:50.0873 0x1468  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
13:51:50.0920 0x1468  mpsdrv - ok
13:51:50.0951 0x1468  [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc          C:\Windows\system32\mpssvc.dll
13:51:50.0998 0x1468  MpsSvc - ok
13:51:51.0029 0x1468  [ 03F899F521D2AAED1C55008F734DF252, 4E56A51476A13F5630719018037B1F63DF9ACEA1CFE782AF04E669BD696954C5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
13:51:51.0044 0x1468  MRxDAV - ok
13:51:51.0076 0x1468  [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
13:51:51.0107 0x1468  mrxsmb - ok
13:51:51.0154 0x1468  [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:51:51.0169 0x1468  mrxsmb10 - ok
13:51:51.0185 0x1468  [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:51:51.0200 0x1468  mrxsmb20 - ok
13:51:51.0216 0x1468  [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci          C:\Windows\system32\drivers\msahci.sys
13:51:51.0216 0x1468  msahci - ok
13:51:51.0325 0x1468  [ B03E3F64B70F8031E65EB26DA23DE91A, 73184B4A75C1EA5D10B9D78A9E705432551DE15231F10C5A31021896D0938D80 ] MSCamSvc        C:\Program Files\Microsoft LifeCam\MSCamS32.exe
13:51:51.0341 0x1468  MSCamSvc - ok
13:51:51.0372 0x1468  [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
13:51:51.0388 0x1468  msdsm - ok
13:51:51.0403 0x1468  [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC          C:\Windows\System32\msdtc.exe
13:51:51.0434 0x1468  MSDTC - ok
13:51:51.0450 0x1468  [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs            C:\Windows\system32\drivers\Msfs.sys
13:51:51.0466 0x1468  Msfs - ok
13:51:51.0481 0x1468  [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
13:51:51.0497 0x1468  mshidkmdf - ok
13:51:51.0512 0x1468  [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
13:51:51.0512 0x1468  msisadrv - ok
13:51:51.0575 0x1468  [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
13:51:51.0622 0x1468  MSiSCSI - ok
13:51:51.0622 0x1468  msiserver - ok
13:51:51.0668 0x1468  [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
13:51:51.0700 0x1468  MSKSSRV - ok
13:51:51.0715 0x1468  [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
13:51:51.0731 0x1468  MSPCLOCK - ok
13:51:51.0731 0x1468  [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
13:51:51.0746 0x1468  MSPQM - ok
13:51:51.0746 0x1468  [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
13:51:51.0762 0x1468  MsRPC - ok
13:51:51.0778 0x1468  [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
13:51:51.0778 0x1468  mssmbios - ok
13:51:51.0778 0x1468  [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
13:51:51.0793 0x1468  MSTEE - ok
13:51:51.0824 0x1468  [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
13:51:51.0856 0x1468  MTConfig - ok
13:51:51.0887 0x1468  [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup            C:\Windows\system32\Drivers\mup.sys
13:51:51.0902 0x1468  Mup - ok
13:51:51.0980 0x1468  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent        C:\Windows\system32\qagentRT.dll
13:51:51.0996 0x1468  napagent - ok
13:51:52.0074 0x1468  [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
13:51:52.0105 0x1468  NativeWifiP - ok
13:51:52.0136 0x1468  [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 ] NDIS            C:\Windows\system32\drivers\ndis.sys
13:51:52.0152 0x1468  NDIS - ok
13:51:52.0199 0x1468  [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
13:51:52.0214 0x1468  NdisCap - ok
13:51:52.0261 0x1468  [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
13:51:52.0308 0x1468  NdisTapi - ok
13:51:52.0324 0x1468  [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
13:51:52.0370 0x1468  Ndisuio - ok
13:51:52.0370 0x1468  [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
13:51:52.0448 0x1468  NdisWan - ok
13:51:52.0464 0x1468  [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
13:51:52.0480 0x1468  NDProxy - ok
13:51:52.0526 0x1468  [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
13:51:52.0558 0x1468  NetBIOS - ok
13:51:52.0604 0x1468  [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
13:51:52.0667 0x1468  NetBT - ok
13:51:52.0682 0x1468  [ F65F365AC0D1657917EFDB52445C848B, 1BDCEFED2799B5507B28B4D72D13D2DD7A1102B21F3938E98BA65737985A4ED9 ] Netlogon        C:\Windows\system32\lsass.exe
13:51:52.0698 0x1468  Netlogon - ok
13:51:52.0714 0x1468  [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman          C:\Windows\System32\netman.dll
13:51:52.0745 0x1468  Netman - ok
13:51:52.0885 0x1468  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:51:52.0948 0x1468  NetMsmqActivator - ok
13:51:52.0963 0x1468  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:51:52.0963 0x1468  NetPipeActivator - ok
13:51:52.0994 0x1468  [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm        C:\Windows\System32\netprofm.dll
13:51:53.0010 0x1468  netprofm - ok
13:51:53.0010 0x1468  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:51:53.0026 0x1468  NetTcpActivator - ok
13:51:53.0026 0x1468  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:51:53.0026 0x1468  NetTcpPortSharing - ok
13:51:53.0104 0x1468  [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
13:51:53.0119 0x1468  nfrd960 - ok
13:51:53.0150 0x1468  [ F115C5CD29E512F18BD7138A094B77E5, 90C2CE8B256EE9AABF674ADDE7F85E91DAF48EA368452D03C187A4AE027D4E39 ] NlaSvc          C:\Windows\System32\nlasvc.dll
13:51:53.0197 0x1468  NlaSvc - ok
13:51:53.0275 0x1468  nlndis - ok
13:51:53.0447 0x1468  [ 1B49B83747509B2B1D707CD4B09AA504, C84689E52D184C9D358514DB36A6E6D3CD306C51A70D93853F1E3E8AF39B3F68 ] NLNdisMP        C:\Windows\system32\DRIVERS\nlndis.sys
13:51:53.0525 0x1468  NLNdisMP - ok
13:51:53.0681 0x1468  [ 1B49B83747509B2B1D707CD4B09AA504, C84689E52D184C9D358514DB36A6E6D3CD306C51A70D93853F1E3E8AF39B3F68 ] NLNdisPT        C:\Windows\system32\DRIVERS\nlndis.sys
13:51:53.0759 0x1468  NLNdisPT - ok
13:51:53.0852 0x1468  [ B4D07CD366F5D40138ABB68600FC8CDE, 98FC3EA99BC2AB5DC59588AEAC500B1404D7B4CCBBF2FDC4E4BDC48808EDBB21 ] nlsvc          C:\Program Files\NetLimiter 3\nlsvc.exe
13:51:53.0868 0x1468  nlsvc - detected UnsignedFile.Multi.Generic ( 1 )
13:51:55.0163 0x1468  nlsvc ( UnsignedFile.Multi.Generic ) - warning
13:51:55.0849 0x1468  [ 6FE26694C94F1A63AF066D7A557F69D3, 70E3354BBA2F9E2FF988C191AA0E72E1E4B56F5F4DB4B8F60F0628C674DF4462 ] nltdi          C:\Program Files\NetLimiter 3\nltdi.sys
13:51:55.0927 0x1468  nltdi - ok
13:51:56.0005 0x1468  [ 25401B0C9576C8456B3E0BBD74FF0771, BB569C99360A631850537DC2EDA0BF85D091CC30BD98B3FD2AC9DABDFB7741DA ] NPF            C:\Windows\system32\drivers\npf.sys
13:51:56.0021 0x1468  NPF - ok
13:51:56.0036 0x1468  [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
13:51:56.0083 0x1468  Npfs - ok
13:51:56.0099 0x1468  [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi            C:\Windows\system32\nsisvc.dll
13:51:56.0114 0x1468  nsi - ok
13:51:56.0114 0x1468  [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
13:51:56.0146 0x1468  nsiproxy - ok
13:51:56.0192 0x1468  [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
13:51:56.0224 0x1468  Ntfs - ok
13:51:56.0317 0x1468  [ 170EE229D4DEF31DBE95348C9A88FE74, EB416066543CBEE991698E18E1EE058696B1D650837279F1BF33C29C19A6CE6B ] ntk_PowerDVD    C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys
13:51:56.0333 0x1468  ntk_PowerDVD - ok
13:51:56.0333 0x1468  [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null            C:\Windows\system32\drivers\Null.sys
13:51:56.0380 0x1468  Null - ok
13:51:56.0504 0x1468  [ F69FD161BD904778E1D6EBE9EEBBC2B5, 463887665C45639E87D7371CB59032193FFC1A2E18D0E21E1709D40D03048AE9 ] NVHDA          C:\Windows\system32\drivers\nvhda32v.sys
13:51:56.0536 0x1468  NVHDA - ok
13:51:56.0911 0x1468  [ FCEA6786A7222DF6C26B008279139952, 9E96776417B45DC1ABDA5DE0CD36913FC6E6A38486D470BCBE01D09CE7388C4A ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:51:57.0021 0x1468  nvlddmkm - ok
13:51:57.0068 0x1468  [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
13:51:57.0068 0x1468  nvraid - ok
13:51:57.0099 0x1468  [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
13:51:57.0099 0x1468  nvstor - ok
13:51:57.0130 0x1468  NvStUSB - ok
13:51:57.0193 0x1468  [ F4B2AAFDB72CC6A54A14A0D6DC82657A, CBC6F3E8BEE4920886A4A3F3269132719E520898590104BCD3391D77F435FD13 ] nvsvc          C:\Windows\system32\nvvsvc.exe
13:51:57.0224 0x1468  nvsvc - ok
13:51:57.0255 0x1468  nvvad_WaveExtensible - ok
13:51:57.0286 0x1468  [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
13:51:57.0302 0x1468  nv_agp - ok
13:51:57.0318 0x1468  [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
13:51:57.0333 0x1468  ohci1394 - ok
13:51:57.0505 0x1468  [ 92831BAF6F475F342F1F9605B27C354D, 0915AE09E3E8B9B3BC4C7B9B90BB7993317F62FC78C26F0318A2A838857A3EA8 ] OODefragAgent  C:\Program Files\OO Software\Defrag\oodag.exe
13:51:57.0536 0x1468  OODefragAgent - ok
13:51:57.0661 0x1468  [ BFAEDDE456C73BB28363D7176BB1820D, 7F33F6084A29E9334479AA797A07DC958986B32785C578D281FDA8682887BF6F ] OpenVPNService  C:\Program Files\OpenVPN\bin\openvpnserv.exe
13:51:57.0676 0x1468  OpenVPNService - ok
13:51:57.0864 0x1468  [ 4E2D0656946F2A19FED1C60E0E4FC1AF, 5551D5BD89EB650C5485BBB58DAA5473044B7C967B72687A27430FA9A1E812FE ] Origin Client Service C:\Program Files\Origin\OriginClientService.exe
13:51:57.0895 0x1468  Origin Client Service - ok
13:51:57.0973 0x1468  [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose            C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:51:57.0988 0x1468  ose - ok
13:51:58.0129 0x1468  [ 358A9CCA612C68EB2F07DDAD4CE1D8D7, F342100E2E9001F11FDF93F856B50FA43F9B85D2C6B5706EC0433E77206498DA ] osppsvc        C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
13:51:58.0191 0x1468  osppsvc - ok
13:51:58.0222 0x1468  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
13:51:58.0238 0x1468  p2pimsvc - ok
13:51:58.0269 0x1468  [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc          C:\Windows\system32\p2psvc.dll
13:51:58.0285 0x1468  p2psvc - ok
13:51:58.0363 0x1468  [ 9DC0BA8730B8FE61D3B71A3EEF2E836F, 1022721977D86C45B0649C9C6AAB44B9E52917DF5D82FBA17A7219826A846180 ] ParagonLDM      C:\Windows\system32\drivers\biont_bs.sys
13:51:58.0378 0x1468  ParagonLDM - ok
13:51:58.0456 0x1468  [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport        C:\Windows\system32\drivers\parport.sys
13:51:58.0488 0x1468  Parport - ok
13:51:58.0503 0x1468  [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr        C:\Windows\system32\drivers\partmgr.sys
13:51:58.0519 0x1468  partmgr - ok
13:51:58.0519 0x1468  [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm          C:\Windows\system32\drivers\parvdm.sys
13:51:58.0534 0x1468  Parvdm - ok
13:51:58.0550 0x1468  [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc          C:\Windows\System32\pcasvc.dll
13:51:58.0566 0x1468  PcaSvc - ok
13:51:58.0581 0x1468  [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci            C:\Windows\system32\drivers\pci.sys
13:51:58.0581 0x1468  pci - ok
13:51:58.0597 0x1468  [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide          C:\Windows\system32\drivers\pciide.sys
13:51:58.0597 0x1468  pciide - ok
13:51:58.0612 0x1468  [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
13:51:58.0628 0x1468  pcmcia - ok
13:51:58.0628 0x1468  [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw            C:\Windows\system32\drivers\pcw.sys
13:51:58.0644 0x1468  pcw - ok
13:51:58.0706 0x1468  [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
13:51:58.0737 0x1468  PEAUTH - ok
13:51:58.0768 0x1468  [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc    C:\Windows\system32\peerdistsvc.dll
13:51:58.0800 0x1468  PeerDistSvc - ok
13:51:58.0831 0x1468  [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla            C:\Windows\system32\pla.dll
13:51:58.0878 0x1468  pla - ok
13:51:58.0956 0x1468  [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
13:51:58.0987 0x1468  PlugPlay - ok
13:51:59.0065 0x1468  [ 713E294439D982BB161317DE0136FAA0, 439DE38F993B3EBFAE7053A90AE5EA47BEEF02E28E261F23CA6A6037FC3676C4 ] pneteth        C:\Windows\system32\DRIVERS\pneteth.sys
13:51:59.0096 0x1468  pneteth - ok
13:51:59.0096 0x1468  [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
13:51:59.0112 0x1468  PNRPAutoReg - ok
13:51:59.0143 0x1468  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
13:51:59.0174 0x1468  PNRPsvc - ok
13:51:59.0236 0x1468  [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
13:51:59.0268 0x1468  PolicyAgent - ok
13:51:59.0268 0x1468  [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power          C:\Windows\system32\umpo.dll
13:51:59.0299 0x1468  Power - ok
13:51:59.0346 0x1468  [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
13:51:59.0392 0x1468  PptpMiniport - ok
13:51:59.0408 0x1468  [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor      C:\Windows\system32\drivers\processr.sys
13:51:59.0424 0x1468  Processor - ok
13:51:59.0517 0x1468  [ FD9692A3D31E021207D3C2A9DDDC2BE3, 5295EFAD9BD4B59996935A41825392C12A4C968D161BEEA37797F90AF8E54229 ] ProfSvc        C:\Windows\system32\profsvc.dll
13:51:59.0533 0x1468  ProfSvc - ok
13:51:59.0548 0x1468  [ F65F365AC0D1657917EFDB52445C848B, 1BDCEFED2799B5507B28B4D72D13D2DD7A1102B21F3938E98BA65737985A4ED9 ] ProtectedStorage C:\Windows\system32\lsass.exe
13:51:59.0548 0x1468  ProtectedStorage - ok
13:51:59.0611 0x1468  [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
13:51:59.0642 0x1468  Psched - ok
13:51:59.0736 0x1468  [ 543A4EF0923BF70D126625B034EF25AF, 9CC82C5221F11850419A796D48D5452B3DEE0C8E8E85A818F4AAA869673F9740 ] PSI_SVC_2      c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
13:51:59.0751 0x1468  PSI_SVC_2 - ok
13:51:59.0814 0x1468  [ 3A6489DCB6F28970B6BBD9687777FA00, 23F8C7B8A4B95925AA53D7F0AA4C349EA38CBEDF31AC9EAC17189CBBEAEF7B5C ] pwdrvio        C:\Windows\system32\pwdrvio.sys
13:51:59.0814 0x1468  pwdrvio - ok
13:51:59.0892 0x1468  [ 9D00D015159B6ADF0980BAEEB5DCC5E4, C944564FD992084E86DD581B73E8DFDA54DBDA8A4396F6675BDA771ED50AF6C5 ] pwdspio        C:\Windows\system32\pwdspio.sys
13:51:59.0892 0x1468  pwdspio - ok
13:51:59.0985 0x1468  [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300          C:\Windows\system32\drivers\ql2300.sys
13:52:00.0001 0x1468  ql2300 - ok
13:52:00.0063 0x1468  [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
13:52:00.0079 0x1468  ql40xx - ok
13:52:00.0110 0x1468  [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE          C:\Windows\system32\qwave.dll
13:52:00.0141 0x1468  QWAVE - ok
13:52:00.0172 0x1468  [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
13:52:00.0188 0x1468  QWAVEdrv - ok
13:52:00.0204 0x1468  [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
13:52:00.0235 0x1468  RasAcd - ok
13:52:00.0282 0x1468  [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
13:52:00.0313 0x1468  RasAgileVpn - ok
13:52:00.0328 0x1468  [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto        C:\Windows\System32\rasauto.dll
13:52:00.0344 0x1468  RasAuto - ok
13:52:00.0344 0x1468  [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
13:52:00.0360 0x1468  Rasl2tp - ok
13:52:00.0375 0x1468  [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan          C:\Windows\System32\rasmans.dll
13:52:00.0391 0x1468  RasMan - ok
13:52:00.0406 0x1468  [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
13:52:00.0422 0x1468  RasPppoe - ok
13:52:00.0453 0x1468  [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
13:52:00.0516 0x1468  RasSstp - ok
13:52:00.0687 0x1468  [ 67EAD2898F681B4ECA6E385AA39C8539, BD3D46234DD4FB6232CFF073E75CA8E35E06B416D205DCD6564E30D7548ED6F6 ] Razer Game Scanner Service C:\Program Files\Razer\Razer Services\GSS\GameScannerService.exe
13:52:00.0703 0x1468  Razer Game Scanner Service - ok
13:52:00.0718 0x1468  [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
13:52:00.0750 0x1468  rdbss - ok
13:52:00.0796 0x1468  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus          C:\Windows\system32\drivers\rdpbus.sys
13:52:00.0812 0x1468  rdpbus - ok
13:52:00.0828 0x1468  [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
13:52:00.0859 0x1468  RDPCDD - ok
13:52:00.0890 0x1468  [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR          C:\Windows\system32\drivers\rdpdr.sys
13:52:00.0906 0x1468  RDPDR - ok
13:52:00.0937 0x1468  [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
13:52:00.0984 0x1468  RDPENCDD - ok
13:52:00.0984 0x1468  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
13:52:01.0015 0x1468  RDPREFMP - ok
13:52:01.0108 0x1468  [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
13:52:01.0124 0x1468  RDPWD - ok
13:52:01.0202 0x1468  [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
13:52:01.0218 0x1468  rdyboost - ok
13:52:01.0467 0x1468  [ BBFCAC1C23B867AE5D7EF96DF40680C5, D7A60D2B1AA96F93A797778B6B2D2663C1F18CA0990298EC4D7B6F4E959481F4 ] Realtek87B      C:\Program Files\Realtek\RTL8187 Wireless LAN Utility\RtlService.exe
13:52:01.0467 0x1468  Realtek87B - detected UnsignedFile.Multi.Generic ( 1 )
13:52:02.0076 0x1468  Detect skipped due to KSN trusted
13:52:02.0076 0x1468  Realtek87B - ok
13:52:02.0107 0x1468  [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess    C:\Windows\System32\mprdim.dll
13:52:02.0122 0x1468  RemoteAccess - ok
13:52:02.0169 0x1468  [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry  C:\Windows\system32\regsvc.dll
13:52:02.0200 0x1468  RemoteRegistry - ok
13:52:02.0247 0x1468  [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
13:52:02.0278 0x1468  RpcEptMapper - ok
13:52:02.0294 0x1468  [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator      C:\Windows\system32\locator.exe
13:52:02.0325 0x1468  RpcLocator - ok
13:52:02.0341 0x1468  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs          C:\Windows\system32\rpcss.dll
13:52:02.0356 0x1468  RpcSs - ok
13:52:02.0481 0x1468  [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
13:52:02.0528 0x1468  rspndr - ok
13:52:02.0793 0x1468  [ 0867F0EC74C8DC997F078F427E611169, 901839DA4AC9FFED00A030F4108078C92D59D7F91380CE725513866252E351E3 ] RTCore32        C:\Program Files\MSI Afterburner\RTCore32.sys
13:52:02.0809 0x1468  RTCore32 - detected UnsignedFile.Multi.Generic ( 1 )
13:52:03.0417 0x1468  Detect skipped due to KSN trusted
13:52:03.0417 0x1468  RTCore32 - ok
13:52:03.0651 0x1468  [ BCB84B430A92AE31940870DF304AE659, 19851270FCB35F958ACE00FA835B44BF31BFE52E0AF8EACC161B217756B6B769 ] RTL8167        C:\Windows\system32\DRIVERS\Rt86win7.sys
13:52:03.0682 0x1468  RTL8167 - ok
13:52:03.0901 0x1468  [ 325590E7E9587459643BA24D2CF73BF2, 92699FF111C597D6DF0AA4CE059F199E3E67CD15E43C102968E3285995FF0079 ] RTL8187        C:\Windows\system32\DRIVERS\rtl8187.sys
13:52:03.0932 0x1468  RTL8187 - ok
13:52:04.0556 0x1468  [ 45F606823EAA469582318C722C76A29D, 1016FBE111638AE369F7C5FF6CA33178FD6CB06D361F3B488DE6C4D85A22253A ] RUBotSrv        C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe
13:52:04.0587 0x1468  RUBotSrv - ok
13:52:04.0712 0x1468  [ 1E80E6B1DF5B1ADA40F9627A44AE2DE1, 2327112FBBC08464C27E1105FE3BEEC51AB9041C528102B4EEB348586014E9AD ] rzendpt        C:\Windows\system32\DRIVERS\rzendpt.sys
13:52:04.0728 0x1468  rzendpt - ok
13:52:04.0977 0x1468  [ 8ACD8981ED99105443896B632F87F300, 03984C0CB52B4B0930403C3E50945D9648EA2AEBE13AC4FF58A2B43AA5B7E990 ] rzpmgrk        C:\Windows\system32\drivers\rzpmgrk.sys
13:52:04.0993 0x1468  rzpmgrk - ok
13:52:05.0071 0x1468  [ 560069DC51D3CC7F9CF1F4E940F93CAE, 16E2B071991B470A76DFF4B6312D3C7E2133AD9AC4B6A62DDA4E32281952FB23 ] rzpnk          C:\Windows\system32\drivers\rzpnk.sys
13:52:05.0102 0x1468  rzpnk - ok
13:52:05.0196 0x1468  [ 28BE53C21C617B86D497BF55D908B3A8, 69BA3C84D6E9E157ED11DD75EB91CAD6F1DD676E508EC4EB251F3EF3D968EFE0 ] rzudd          C:\Windows\system32\DRIVERS\rzudd.sys
13:52:05.0211 0x1468  rzudd - ok
13:52:05.0242 0x1468  [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap          C:\Windows\system32\drivers\vms3cap.sys
13:52:05.0274 0x1468  s3cap - ok
13:52:05.0305 0x1468  [ F65F365AC0D1657917EFDB52445C848B, 1BDCEFED2799B5507B28B4D72D13D2DD7A1102B21F3938E98BA65737985A4ED9 ] SamSs          C:\Windows\system32\lsass.exe
13:52:05.0336 0x1468  SamSs - ok
13:52:05.0586 0x1468  [ 230FD3749904CA045EA5EC0AA14006E9, D7C79238F862B471740AFF4CC3982658D1339795E9EC884A8921EFE2E547D7C3 ] SANDRA          C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP2\WNt500x86\Sandra.sys
13:52:05.0601 0x1468  SANDRA - ok
13:52:05.0617 0x1468  [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
13:52:05.0632 0x1468  sbp2port - ok
13:52:05.0712 0x1468  [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
13:52:05.0759 0x1468  SCardSvr - ok
13:52:05.0822 0x1468  [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
13:52:05.0853 0x1468  scfilter - ok
13:52:06.0024 0x1468  [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule        C:\Windows\system32\schedsvc.dll
13:52:06.0087 0x1468  Schedule - ok
13:52:06.0134 0x1468  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc    C:\Windows\System32\certprop.dll
13:52:06.0165 0x1468  SCPolicySvc - ok
13:52:06.0180 0x1468  [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
13:52:06.0227 0x1468  SDRSVC - ok
13:52:06.0290 0x1468  [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
13:52:06.0352 0x1468  secdrv - ok
13:52:06.0368 0x1468  [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon        C:\Windows\system32\seclogon.dll
13:52:06.0414 0x1468  seclogon - ok
13:52:06.0446 0x1468  [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS            C:\Windows\system32\sens.dll
13:52:06.0461 0x1468  SENS - ok
13:52:06.0508 0x1468  [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
13:52:06.0524 0x1468  SensrSvc - ok
13:52:06.0602 0x1468  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
13:52:06.0648 0x1468  Serenum - ok
13:52:06.0695 0x1468  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial          C:\Windows\system32\DRIVERS\serial.sys
13:52:06.0742 0x1468  Serial - ok
13:52:06.0820 0x1468  [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse        C:\Windows\system32\drivers\sermouse.sys
13:52:06.0867 0x1468  sermouse - ok
13:52:06.0898 0x1468  [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv      C:\Windows\system32\sessenv.dll
13:52:06.0929 0x1468  SessionEnv - ok
13:52:06.0976 0x1468  [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
13:52:07.0007 0x1468  sffdisk - ok
13:52:07.0023 0x1468  [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
13:52:07.0054 0x1468  sffp_mmc - ok
13:52:07.0085 0x1468  [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
13:52:07.0132 0x1468  sffp_sd - ok
13:52:07.0179 0x1468  [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
13:52:07.0210 0x1468  sfloppy - ok
13:52:07.0709 0x1468  [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess    C:\Windows\System32\ipnathlp.dll
13:52:07.0772 0x1468  SharedAccess - ok
13:52:07.0803 0x1468  [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:52:07.0834 0x1468  ShellHWDetection - ok
13:52:07.0912 0x1468  [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp          C:\Windows\system32\drivers\sisagp.sys
13:52:07.0928 0x1468  sisagp - ok
13:52:07.0990 0x1468  [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
13:52:08.0006 0x1468  SiSRaid2 - ok
13:52:08.0052 0x1468  [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
13:52:08.0068 0x1468  SiSRaid4 - ok
13:52:08.0162 0x1468  [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
13:52:08.0193 0x1468  Smb - ok
13:52:08.0255 0x1468  [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
13:52:08.0286 0x1468  SNMPTRAP - ok
13:52:08.0442 0x1468  [ DC8D2952FB6FFBAEC67BD1B93A34DF11, 0BD1523A68900B80ED1BCCB967643525CCA55D4FF4622D0128913690E6BB619E ] speedfan        C:\Windows\system32\speedfan.sys
13:52:08.0458 0x1468  speedfan - ok
13:52:08.0489 0x1468  [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr          C:\Windows\system32\drivers\spldr.sys
13:52:08.0505 0x1468  spldr - ok
13:52:08.0583 0x1468  [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler        C:\Windows\System32\spoolsv.exe
13:52:08.0598 0x1468  Spooler - ok
13:52:08.0770 0x1468  [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc          C:\Windows\system32\sppsvc.exe
13:52:08.0848 0x1468  sppsvc - ok
13:52:08.0895 0x1468  [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify    C:\Windows\system32\sppuinotify.dll
13:52:08.0926 0x1468  sppuinotify - ok
13:52:09.0160 0x1468  [ A199171385BE17973FD800FA91F8F78A, 815091DC5A3506A3C8414B9D0213A61DF8289BA8645289CC9D338820536B42EA ] sptd            C:\Windows\system32\Drivers\sptd.sys
13:52:09.0160 0x1468  Suspicious file ( NoAccess ): C:\Windows\system32\Drivers\sptd.sys. md5: A199171385BE17973FD800FA91F8F78A, sha256: 815091DC5A3506A3C8414B9D0213A61DF8289BA8645289CC9D338820536B42EA
13:52:09.0160 0x1468  sptd - detected LockedFile.Multi.Generic ( 1 )
13:52:09.0768 0x1468  Detect skipped due to KSN trusted
13:52:09.0768 0x1468  sptd - ok
13:52:09.0815 0x1468  [ 7B426B8E809EDF081D771EF429345528, 7ED3E35368CAFD8EB884FBD8B0BF1E2207E5F78374AE69993368E64432D7531B ] sp_rsdrv2      C:\Windows\system32\drivers\sp_rsdrv2.sys
13:52:09.0831 0x1468  sp_rsdrv2 - detected UnsignedFile.Multi.Generic ( 1 )
13:52:10.0470 0x1468  Detect skipped due to KSN trusted
13:52:10.0470 0x1468  sp_rsdrv2 - ok
13:52:10.0689 0x1468  [ 2798E5AA05DACF91DA029005176756F1, 01843A76536D72E258E4841D2522367B7EFD271E12EA00BFF970B41569D6824C ] SQLWriter      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
13:52:10.0704 0x1468  SQLWriter - ok
13:52:10.0798 0x1468  [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv            C:\Windows\system32\DRIVERS\srv.sys
13:52:10.0876 0x1468  srv - ok
13:52:11.0001 0x1468  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
13:52:11.0016 0x1468  srv2 - ok
13:52:11.0048 0x1468  [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
13:52:11.0079 0x1468  srvnet - ok
13:52:11.0157 0x1468  [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
13:52:11.0204 0x1468  SSDPSRV - ok
13:52:11.0250 0x1468  [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc        C:\Windows\system32\sstpsvc.dll
13:52:11.0297 0x1468  SstpSvc - ok
13:52:11.0750 0x1468  [ BE9ACF067442E33FC03056D124A99A52, 63CE301C23E188BCFB1A27AA9E2494B8120561F291364EC271DFFDB20EE57839 ] ST2012_Svc      C:\Program Files\Spyware Terminator\st_rsser.exe
13:52:11.0781 0x1468  ST2012_Svc - ok
13:52:12.0171 0x1468  [ 5FF569CDD4F84E79F0C2EE742FB9368E, 266BB0E06B58BD1D9C793E5BBC0A5819278E62C952032E5D05A7DBF4EEC78292 ] Stereo Service  C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
13:52:12.0186 0x1468  Stereo Service - ok
13:52:12.0233 0x1468  [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor        C:\Windows\system32\drivers\stexstor.sys
13:52:12.0233 0x1468  stexstor - ok
13:52:12.0358 0x1468  [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc          C:\Windows\System32\wiaservc.dll
13:52:12.0420 0x1468  StiSvc - ok
13:52:12.0467 0x1468  [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt        C:\Windows\system32\drivers\vmstorfl.sys
13:52:12.0483 0x1468  storflt - ok
13:52:12.0514 0x1468  [ 0BF669F0A910BEDA4A32258D363AF2A5, 83EEBACDE4F69A2866B69CAA633F5C8B3CB01D88CEDB01B6EA5988E0A25CEE47 ] StorSvc        C:\Windows\system32\storsvc.dll
13:52:12.0561 0x1468  StorSvc - ok
13:52:12.0639 0x1468  [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc        C:\Windows\system32\drivers\storvsc.sys
13:52:12.0654 0x1468  storvsc - ok
13:52:12.0686 0x1468  [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum          C:\Windows\system32\drivers\swenum.sys
13:52:12.0701 0x1468  swenum - ok
13:52:12.0904 0x1468  [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] SwitchBoard    C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
13:52:12.0951 0x1468  SwitchBoard - detected UnsignedFile.Multi.Generic ( 1 )
13:52:13.0590 0x1468  Detect skipped due to KSN trusted
13:52:13.0590 0x1468  SwitchBoard - ok
13:52:13.0637 0x1468  [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv          C:\Windows\System32\swprv.dll
13:52:13.0668 0x1468  swprv - ok
13:52:13.0762 0x1468  [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain        C:\Windows\system32\sysmain.dll
13:52:13.0793 0x1468  SysMain - ok
13:52:13.0809 0x1468  [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
13:52:13.0840 0x1468  TabletInputService - ok
13:52:13.0918 0x1468  [ AB0BCCDE4709F0C3FFA45F6E387DBEAB, 2C4F54B851F491528F9A3E442F11F597DA07E51D4576F96001F64BEEEDB4DA35 ] tap0901        C:\Windows\system32\DRIVERS\tap0901.sys
13:52:13.0980 0x1468  tap0901 - ok
13:52:14.0012 0x1468  [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv        C:\Windows\System32\tapisrv.dll
13:52:14.0043 0x1468  TapiSrv - ok
13:52:14.0043 0x1468  [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS            C:\Windows\System32\tbssvc.dll
13:52:14.0090 0x1468  TBS - ok
13:52:14.0417 0x1468  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
13:52:14.0464 0x1468  Tcpip - ok
13:52:14.0495 0x1468  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
13:52:14.0511 0x1468  TCPIP6 - ok
13:52:14.0542 0x1468  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
13:52:14.0573 0x1468  tcpipreg - ok
13:52:14.0636 0x1468  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
13:52:14.0667 0x1468  TDPIPE - ok
13:52:14.0714 0x1468  [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
13:52:14.0729 0x1468  TDTCP - ok
13:52:14.0760 0x1468  [ 7FE680A3DFA421C4A8E4879AE4C5AAB0, A4C64E155AB2843823CD3586756BA7681CFDEA50812095468221503BBAD30DCD ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
13:52:14.0807 0x1468  tdx - ok
13:52:14.0854 0x1468  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD          C:\Windows\system32\drivers\termdd.sys
13:52:14.0870 0x1468  TermDD - ok
13:52:15.0010 0x1468  [ FCFD4F50419B4BC72E80066DA10D2E54, 7C2314A57A404525F0444986332DBAE0964A3359374671598387051D7AAE72AE ] TermService    C:\Windows\System32\termsrv.dll
13:52:15.0072 0x1468  TermService - ok
13:52:15.0088 0x1468  [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes          C:\Windows\system32\themeservice.dll
13:52:15.0135 0x1468  Themes - ok
13:52:15.0213 0x1468  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER    C:\Windows\system32\mmcss.dll
13:52:15.0244 0x1468  THREADORDER - ok
13:52:15.0291 0x1468  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks          C:\Windows\System32\trkwks.dll
13:52:15.0353 0x1468  TrkWks - ok
13:52:15.0509 0x1468  [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:52:15.0556 0x1468  TrustedInstaller - ok
13:52:15.0603 0x1468  [ 6C5139E4283249518F7743D7043775B3, 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
13:52:15.0618 0x1468  tssecsrv - ok
13:52:15.0634 0x1468  [ FD1D6C73E6333BE727CBCC6054247654, 6F7B9AE1A5986204DB3348D13B303F30FC17624939DA74D6BD114FAEED0FB30E ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
13:52:15.0681 0x1468  TsUsbFlt - ok
13:52:15.0712 0x1468  [ 01246F0BAAD7B68EC0F472AA41E33282, 51F975AF029AD015576FFFA3E88F5DBB8B40C7CD30ECDEDE8AFABCB08C954199 ] TsUsbGD        C:\Windows\system32\drivers\TsUsbGD.sys
13:52:15.0743 0x1468  TsUsbGD - ok
13:52:15.0837 0x1468  [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
13:52:15.0852 0x1468  tunnel - ok
13:52:16.0057 0x1468  [ 0397852EF1E5463D57F22C689F6354F9, 620845F35754DE1772CBC750A1F787C6C5130FFB8CE24DE51ADD2F5921B33477 ] t_mouse.sys    C:\Windows\system32\DRIVERS\t_mouse.sys
13:52:16.0073 0x1468  t_mouse.sys - ok
13:52:16.0135 0x1468  [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
13:52:16.0151 0x1468  uagp35 - ok
13:52:16.0182 0x1468  [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
13:52:16.0213 0x1468  udfs - ok
13:52:16.0244 0x1468  [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect      C:\Windows\system32\UI0Detect.exe
13:52:16.0354 0x1468  UI0Detect - ok
13:52:16.0525 0x1468  [ 950821BFC2951F349540FA16433CA800, 8143FF2967B77E1BBDA5949769A74CD104FEA8AC38C75FB84E911FC6C85ACD18 ] UimBus          C:\Windows\system32\DRIVERS\UimBus.sys
13:52:16.0525 0x1468  UimBus - ok
13:52:16.0619 0x1468  [ 6ABC3943F6FBCE54DAB42E6757CADC0B, 299A393140B40A53BCA756A6A0B5FF86D517462575BA2AB8E27969FF579B50F3 ] Uim_DEVIM      C:\Windows\system32\DRIVERS\uim_devim.sys
13:52:16.0634 0x1468  Uim_DEVIM - ok
13:52:16.0790 0x1468  [ 0EC2117399CADDC2D197DB24C57135FD, 6FDED81FEA785CAD6AA9C626A618C440BA9BDA3E14CBD205B693C093BF9B8FF2 ] Uim_IM          C:\Windows\system32\Drivers\Uim_IM.sys
13:52:16.0822 0x1468  Uim_IM - ok
13:52:16.0931 0x1468  [ AA16B72277CDCE5310DEF8BB8F5DB695, 78462F27BBAD9D44C62A6565F5C4364DEADC0D3F476D5927E0651217F1A59F9D ] Uim_Vim        C:\Windows\system32\Drivers\Uim_Vim.sys
13:52:16.0946 0x1468  Uim_Vim - ok
13:52:17.0058 0x1468  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
13:52:17.0073 0x1468  uliagpkx - ok
13:52:17.0136 0x1468  [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
13:52:17.0167 0x1468  umbus - ok
13:52:17.0214 0x1468  [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass          C:\Windows\system32\drivers\umpass.sys
13:52:17.0229 0x1468  UmPass - ok
13:52:17.0312 0x1468  [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService    C:\Windows\System32\umrdp.dll
13:52:17.0344 0x1468  UmRdpService - ok
13:52:17.0407 0x1468  [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost        C:\Windows\System32\upnphost.dll
13:52:17.0485 0x1468  upnphost - ok
13:52:17.0610 0x1468  [ A1977C315BF5691DA99235AA4A6907AF, 34B52FBA83F0E1C6B001D0AD1808B00152F731D18AAECC3C53B9918AA89BACEC ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
13:52:17.0656 0x1468  usbaudio - ok
13:52:17.0703 0x1468  [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
13:52:17.0734 0x1468  usbccgp - ok
13:52:17.0797 0x1468  [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir          C:\Windows\system32\drivers\usbcir.sys
13:52:17.0828 0x1468  usbcir - ok
13:52:17.0890 0x1468  [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci        C:\Windows\system32\drivers\usbehci.sys
13:52:17.0922 0x1468  usbehci - ok
13:52:18.0031 0x1468  [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
13:52:18.0078 0x1468  usbhub - ok
13:52:18.0124 0x1468  [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
13:52:18.0171 0x1468  usbohci - ok
13:52:18.0265 0x1468  [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
13:52:18.0280 0x1468  usbprint - ok
13:52:18.0358 0x1468  [ FC6B21DB4B5B398AB93DBE59CBF11036, A94094C208F376405C07822A6143001EF1B12AE93205CD8002E87F6EB45F6374 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
13:52:18.0374 0x1468  usbscan - ok
13:52:18.0468 0x1468  [ 007C0C8D5B01D82ACEB70431D15083F6, 7EAF68CD3C38D3CD2CDFEE9ECE1DFB38E274F1F9E6F70B73BCE1336E87D5496C ] usbser          C:\Windows\system32\DRIVERS\usbser.sys
13:52:18.0514 0x1468  usbser - ok
13:52:18.0546 0x1468  [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:52:18.0577 0x1468  USBSTOR - ok
13:52:18.0608 0x1468  [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
13:52:18.0639 0x1468  usbuhci - ok
13:52:18.0780 0x1468  [ DE014425522610BEDCA3821BB8C0F1D5, D6FEA0DF07F89834AEEE8C02CC7FD41068D758B6CCECE2EEE5CF4B9DB646FA1E ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
13:52:18.0811 0x1468  usbvideo - ok
13:52:18.0826 0x1468  [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms          C:\Windows\System32\uxsms.dll
13:52:18.0858 0x1468  UxSms - ok
13:52:18.0873 0x1468  [ F65F365AC0D1657917EFDB52445C848B, 1BDCEFED2799B5507B28B4D72D13D2DD7A1102B21F3938E98BA65737985A4ED9 ] VaultSvc        C:\Windows\system32\lsass.exe
13:52:18.0889 0x1468  VaultSvc - ok
13:52:19.0216 0x1468  [ 7C1842F09D57B8855459B86AAD9C97E1, 86E76FA59CCDDC0FECC54444B5017F159F2058DDF6B356AA5C9CB314F4DA7541 ] VBoxDrv        C:\Windows\system32\DRIVERS\VBoxDrv.sys
13:52:19.0248 0x1468  VBoxDrv - ok
13:52:19.0388 0x1468  [ 67F5898F8111800D4C7639A6599F2EC3, C1436F16BD9D9EDB686D92A5DA793DF64665826641FDF99191C4D27CE5C65B7C ] VBoxNetAdp      C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
13:52:19.0404 0x1468  VBoxNetAdp - ok
13:52:19.0560 0x1468  [ F735FC8C580DAEB449BEF8CF2626516C, F4F316829C3D9A62D83326732003ABAAF99024C43F02DD1E8F94C5EA3EE6E842 ] VBoxUSBMon      C:\Windows\system32\DRIVERS\VBoxUSBMon.sys
13:52:19.0591 0x1468  VBoxUSBMon - ok
13:52:19.0794 0x1468  [ 2BE85EECCC3F537C685ACF0FC4D5341C, 13FB079C220D6EB29515ED293C97DAAA6CE364C00B67B2D2251E742412DCEFAD ] VC10SecS        C:\Program Files\Virtual CD v10\System\VC10SecS.exe
13:52:19.0809 0x1468  VC10SecS - ok
13:52:19.0809 0x1468  Suspicious service (NoAccess): vdrv1000
13:52:19.0981 0x1468  [ F1382BD8FDD95A3ACD5E0D88015DC2E7, 6AB88512BDD7F19F298F17FE561F1011D5E83DF9C2318C9B59473A95CB3FA449 ] vdrv1000        C:\Windows\system32\DRIVERS\vdrv1000.sys
13:52:19.0996 0x1468  vdrv1000 - detected LockedService.Multi.Generic ( 1 )
13:52:20.0605 0x1468  Detect skipped due to KSN trusted
13:52:20.0605 0x1468  vdrv1000 - ok
13:52:20.0792 0x1468  [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
13:52:20.0808 0x1468  vdrvroot - ok
13:52:20.0964 0x1468  [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds            C:\Windows\System32\vds.exe
13:52:20.0995 0x1468  vds - ok
13:52:21.0073 0x1468  [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
13:52:21.0120 0x1468  vga - ok
13:52:21.0151 0x1468  [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave        C:\Windows\System32\drivers\vga.sys
13:52:21.0182 0x1468  VgaSave - ok
13:52:21.0244 0x1468  [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
13:52:21.0260 0x1468  vhdmp - ok
13:52:21.0338 0x1468  [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
13:52:21.0354 0x1468  viaagp - ok
13:52:21.0385 0x1468  [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7          C:\Windows\system32\drivers\viac7.sys
13:52:21.0416 0x1468  ViaC7 - ok
13:52:21.0463 0x1468  [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide          C:\Windows\system32\drivers\viaide.sys
13:52:21.0478 0x1468  viaide - ok
13:52:21.0853 0x1468  [ 2562943B90AFA9829097FB4274276D1D, EE003EF7A3EC49CFEF2EED841482721D7A89368967BFC44CE8DD9D3BDAF0572F ] VMAuthdService  C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
13:52:21.0868 0x1468  VMAuthdService - ok
13:52:21.0915 0x1468  [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus          C:\Windows\system32\drivers\vmbus.sys
13:52:21.0915 0x1468  vmbus - ok
13:52:21.0931 0x1468  [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
13:52:21.0946 0x1468  VMBusHID - ok
13:52:21.0993 0x1468  [ D644FFEA14778DDA59BDA8492BCED4B6, 5146A0181AEED5727C729DE451B3F2070FF8DD4A0B32AD6BD3DEB42232B5FAE1 ] vmci            C:\Windows\system32\DRIVERS\vmci.sys
13:52:22.0009 0x1468  vmci - ok
13:52:22.0087 0x1468  [ 5BADB72A9A880660BC966DC97237207B, 254BF9B4CCF70133F340E752018A4C2C139226E6ECF931962811780DD55F2841 ] vmkbd2          C:\Windows\system32\drivers\VMkbd.sys
13:52:22.0102 0x1468  vmkbd2 - ok
13:52:22.0134 0x1468  [ 872DE8E16A2821804D8E4EC76A1E38B4, 346C2EDE1A0AEA3A1B2D4C3066B1AF94FFC00B5D3401E323C0FD46D8D824C563 ] VMnetAdapter    C:\Windows\system32\DRIVERS\vmnetadapter.sys
13:52:22.0134 0x1468  VMnetAdapter - ok
13:52:22.0180 0x1468  [ 2ECECADD1F5AE56F297B81F2AC464B03, 6EA6EDE53AE420EF750A14045399AAD77D07C80324C0C60E74127E350C7E7090 ] VMnetBridge    C:\Windows\system32\DRIVERS\vmnetbridge.sys
13:52:22.0196 0x1468  VMnetBridge - ok
13:52:22.0227 0x1468  [ 05A869D1B12B08B5601487CA534B5021, 07A4BE681C0C0B23CBD5C05715DAA887D4DDE6D99251BC5D748F321940C23315 ] VMnetDHCP      C:\Windows\system32\vmnetdhcp.exe
13:52:22.0243 0x1468  VMnetDHCP - ok
13:52:22.0258 0x1468  [ 448788D4D9C6E7F20BA7C6487B52D44E, 8643B237262099998049D23B5BE1F65C224500E8947B2FAC798B5A00132082A4 ] VMnetuserif    C:\Windows\system32\drivers\vmnetuserif.sys
13:52:22.0274 0x1468  VMnetuserif - ok
13:52:22.0383 0x1468  [ F3922FB27510E28FAC82A0DC442A900E, 11D42F62460647EADFABC29873D20CC77B117B676D30655B7919A1C0EBBFA86F ] VMUSBArbService C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
13:52:22.0399 0x1468  VMUSBArbService - ok
13:52:22.0446 0x1468  [ F13B73E932CACDDE5ED825BDF7AA9637, 4B6C8D82324314294AE439ACDE933E6C8E77635ADE933BC52A0CD9A68927702D ] VMware NAT Service C:\Windows\system32\vmnat.exe
13:52:22.0461 0x1468  VMware NAT Service - ok
13:52:22.0789 0x1468  [ 5591F0BB3713AB911D4021124D1FDB54, 21AB28EABBAFC41E7FF4F318D03785274EB842DCD8BDED814155FB29413769D7 ] VMwareHostd    C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe
13:52:22.0992 0x1468  VMwareHostd - ok
13:52:23.0038 0x1468  [ E80257E1A4B5A905857705FF5C4787AE, AA354C4A46A0B7D13584FACB9EBF699820E24D18B3EFD830E5E811C7F16BD1B4 ] vmx86          C:\Windows\system32\Drivers\vmx86.sys
13:52:23.0054 0x1468  vmx86 - ok
13:52:23.0085 0x1468  [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
13:52:23.0085 0x1468  volmgr - ok
13:52:23.0116 0x1468  [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
13:52:23.0132 0x1468  volmgrx - ok
13:52:23.0148 0x1468  [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
13:52:23.0148 0x1468  volsnap - ok
13:52:23.0210 0x1468  [ B26536ADD1D748CDA104D856C979AE79, C88FBCD63DB3607232616FAB989F0FD7FB00ED542E6AC1BC76076A7C13A6FB22 ] vpcbus          C:\Windows\system32\DRIVERS\vpchbus.sys
13:52:23.0226 0x1468  vpcbus - ok
13:52:23.0257 0x1468  [ A0F7E923A6261760130F22B85DF9040E, E70ED14497262C75CC2D4B67B046BB43D8F47A4B8487D258694891E9B4C6DA44 ] vpcnfltr        C:\Windows\system32\DRIVERS\vpcnfltr.sys
13:52:23.0319 0x1468  vpcnfltr - ok
13:52:23.0335 0x1468  [ 5F4B55E91CE7E2523C9E1E0ECE858869, 3C395198C1845A15C4E39888383587A5E481E2761B885DBB5FC2C17C7075E6B4 ] vpcusb          C:\Windows\system32\DRIVERS\vpcusb.sys
13:52:23.0382 0x1468  vpcusb - ok
13:52:23.0444 0x1468  [ B487191FE18D6863381A1AC55482469A, 77A6C87E833E90FFD2FF51C6B28041D8AE9C6CE293DA4166E65470C18C017971 ] vpcvmm          C:\Windows\system32\drivers\vpcvmm.sys
13:52:23.0475 0x1468  vpcvmm - ok
13:52:23.0522 0x1468  [ 9257FF91AEA61F05B200F2CBBDB67BDF, CCFC55843B526E483D31DD0FC723E5D346D78352861F6ECBC3EAD07145F317D1 ] Vsdatant        C:\Windows\system32\drivers\vsdatant.sys
13:52:23.0538 0x1468  Vsdatant - ok
13:52:23.0709 0x1468  [ ABC70D66394C27F0B50E41A19E89C2D7, EFB1354DDB5599D13D5397EB34EC865D7F23344650C64C5A04622430A6B22B77 ] vsmon          C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
13:52:23.0756 0x1468  vsmon - ok
13:52:23.0803 0x1468  [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
13:52:23.0818 0x1468  vsmraid - ok
13:52:23.0850 0x1468  [ 843081D296F617DDFAE4D70F2564C852, A2F0A31AE740850996E1595E0C21E3365387B049480999ACA8DE2AE5394232E2 ] vsock          C:\Windows\system32\drivers\vsock.sys
13:52:23.0865 0x1468  vsock - ok
13:52:23.0912 0x1468  [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS            C:\Windows\system32\vssvc.exe
13:52:23.0959 0x1468  VSS - ok
13:52:24.0037 0x1468  [ 43725C38A00C5667AD8CA82C1790D465, 3E06294DADE18CE1D103363C85A6F22FF53F076AE41E8772362C747B2DC16E3E ] vstor2-mntapi20-shared C:\Windows\system32\drivers\vstor2-mntapi20-shared.sys
13:52:24.0052 0x1468  vstor2-mntapi20-shared - ok
13:52:24.0084 0x1468  [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
13:52:24.0099 0x1468  vwifibus - ok
13:52:24.0115 0x1468  [ 7090D3436EEB4E7DA3373090A23448F7, 3A130B28F2BFA7DCEC8596C4CE4E187B019F5ECF1AAC8DD1BBDE9CBD2428FEC2 ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
13:52:24.0146 0x1468  vwififlt - ok
13:52:24.0193 0x1468  [ A3F04CBEA6C2A10E6CB01F8B47611882, 32AFE18B07FECA30BC95831A5DC94C784E543784DF16165334A777DC84E91EF3 ] vwifimp        C:\Windows\system32\DRIVERS\vwifimp.sys
13:52:24.0224 0x1468  vwifimp - ok
13:52:24.0255 0x1468  [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time        C:\Windows\system32\w32time.dll
13:52:24.0286 0x1468  W32Time - ok
13:52:24.0318 0x1468  [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
13:52:24.0333 0x1468  WacomPen - ok
13:52:24.0364 0x1468  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
13:52:24.0380 0x1468  WANARP - ok
13:52:24.0380 0x1468  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
13:52:24.0396 0x1468  Wanarpv6 - ok
13:52:24.0458 0x1468  [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine        C:\Windows\system32\wbengine.exe
13:52:24.0489 0x1468  wbengine - ok
13:52:24.0505 0x1468  [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
13:52:24.0520 0x1468  WbioSrvc - ok
13:52:24.0614 0x1468  [ 70FF13D0C853ACEA859737EC8A8D220F, 71AA16F732840EFC8DBE84C0A7C36A8036F3DDB48A289FC7DC249C2ADCEF3E89 ] WCMVCAM        C:\Windows\system32\DRIVERS\wcmvcam.sys
13:52:24.0645 0x1468  WCMVCAM - ok
13:52:24.0661 0x1468  [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc        C:\Windows\System32\wcncsvc.dll
13:52:24.0676 0x1468  wcncsvc - ok
13:52:24.0692 0x1468  [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:52:24.0692 0x1468  WcsPlugInService - ok
13:52:24.0723 0x1468  [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd              C:\Windows\system32\drivers\wd.sys
13:52:24.0723 0x1468  Wd - ok
13:52:24.0786 0x1468  [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
13:52:24.0786 0x1468  Wdf01000 - ok
13:52:24.0801 0x1468  [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost  C:\Windows\system32\wdi.dll
13:52:24.0817 0x1468  WdiServiceHost - ok
13:52:24.0832 0x1468  [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost  C:\Windows\system32\wdi.dll
13:52:24.0832 0x1468  WdiSystemHost - ok
13:52:24.0864 0x1468  [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient      C:\Windows\System32\webclnt.dll
13:52:24.0895 0x1468  WebClient - ok
13:52:24.0910 0x1468  [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc          C:\Windows\system32\wecsvc.dll
13:52:24.0926 0x1468  Wecsvc - ok
13:52:24.0926 0x1468  [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
13:52:24.0942 0x1468  wercplsupport - ok
13:52:24.0988 0x1468  [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc          C:\Windows\System32\WerSvc.dll
13:52:25.0020 0x1468  WerSvc - ok
13:52:25.0082 0x1468  [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
13:52:25.0098 0x1468  WfpLwf - ok
13:52:25.0098 0x1468  [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
13:52:25.0113 0x1468  WIMMount - ok
13:52:25.0160 0x1468  [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend      C:\Program Files\Windows Defender\mpsvc.dll
13:52:25.0207 0x1468  WinDefend - ok
13:52:25.0222 0x1468  WinHttpAutoProxySvc - ok
13:52:25.0285 0x1468  [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
13:52:25.0316 0x1468  Winmgmt - ok
13:52:25.0394 0x1468  [ 1DE9BD23AFA36150586C732D876D9B74, 32CF2C8EC18CFDA677AB72A182EB4B839DCC72BFCD6CA309BE2F434991CAE973 ] WinRM          C:\Windows\system32\WsmSvc.dll
13:52:25.0441 0x1468  WinRM - ok
13:52:25.0519 0x1468  [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
13:52:25.0534 0x1468  WinUsb - ok
13:52:25.0644 0x1468  [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc        C:\Windows\System32\wlansvc.dll
13:52:25.0675 0x1468  Wlansvc - ok
13:52:26.0158 0x1468  [ 5144AE67D60EC653F97DDF3FEED29E77, F6238767284B2356A9F502E2ACCFAAC283FA13CBF238E98B5115A55179526B10 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
13:52:26.0190 0x1468  wlidsvc - ok
13:52:26.0252 0x1468  [ 1F596392149CAC51F7C095AF7D533934, 7D8649D951E7719DE49B5E7BA4296A0736753A73FE30A45F96F370ADD81E6B2B ] WmHidLo        C:\Windows\system32\drivers\WmHidLo.sys
13:52:26.0252 0x1468  WmHidLo - ok
13:52:26.0314 0x1468  [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
13:52:26.0314 0x1468  WmiAcpi - ok
13:52:26.0330 0x1468  [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
13:52:26.0361 0x1468  wmiApSrv - ok
13:52:26.0455 0x1468  [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc  C:\Program Files\Windows Media Player\wmpnetwk.exe
13:52:26.0486 0x1468  WMPNetworkSvc - ok
13:52:26.0548 0x1468  [ 6F04646BC690F8BBFC344BE32A60796D, DE2B4BE88CE38D6297F58BE2C643A3838C0470E2E3AB6289755E39B5E59061D7 ] WmVirHid        C:\Windows\system32\drivers\WmVirHid.sys
13:52:26.0564 0x1468  WmVirHid - ok
13:52:26.0626 0x1468  [ 1D6CA43D562333F4DFB40BCEF2453F3A, BEEC5587ACE8ABF1DB0B9B68E43B29082AA2F4A6415CEC8536086944D506A704 ] WmXlCore        C:\Windows\system32\drivers\WmXlCore.sys
13:52:26.0626 0x1468  WmXlCore - ok
13:52:26.0642 0x1468  [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
13:52:26.0658 0x1468  WPCSvc - ok
13:52:26.0673 0x1468  [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
13:52:26.0689 0x1468  WPDBusEnum - ok
13:52:26.0704 0x1468  [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
13:52:26.0736 0x1468  ws2ifsl - ok
13:52:26.0751 0x1468  [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc          C:\Windows\system32\wscsvc.dll
13:52:26.0767 0x1468  wscsvc - ok
13:52:26.0767 0x1468  WSearch - ok
13:52:26.0845 0x1468  [ D9B0134913E5EF007AF82A418C503322, 7418DD28C8E968674382F8352AAFFC4DE77887E2B71B8844D615F19432B4C55A ] wuauserv        C:\Windows\system32\wuaueng.dll
13:52:26.0892 0x1468  wuauserv - ok
13:52:26.0907 0x1468  [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
13:52:26.0938 0x1468  WudfPf - ok
13:52:26.0985 0x1468  [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
13:52:27.0016 0x1468  WUDFRd - ok
13:52:27.0063 0x1468  [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
13:52:27.0094 0x1468  wudfsvc - ok
13:52:27.0126 0x1468  [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc        C:\Windows\System32\wwansvc.dll
13:52:27.0141 0x1468  WwanSvc - ok
13:52:27.0297 0x1468  [ DAA74DB95EB93E7493884FCB71F90617, 5368B179479A5C4F061D8FF4DE18AEF39A14855ACFBA1D47A21BDB67697CE649 ] WZCOOK          C:\Users\Friedrich\Desktop\Exploit Sets\aircrack 2.1\win32\wzcook.exe
13:52:27.0313 0x1468  WZCOOK - detected UnsignedFile.Multi.Generic ( 1 )
13:52:28.0218 0x1468  Detect skipped due to KSN trusted
13:52:28.0218 0x1468  WZCOOK - ok
13:52:28.0342 0x1468  [ CE0C846127D6ABB1E2A22E59682B2527, 9FDDECDC964A2E0AD306C68E1CF6B8B77388BBD0EC7642B61EE03273381777F7 ] xnacc          C:\Windows\system32\DRIVERS\xnacc.sys
13:52:28.0374 0x1468  xnacc - ok
13:52:28.0452 0x1468  [ 276842A27953BE204A2507096F09B1F3, 9D614C5D3BB679CCF15CA6DD044318692EA6D89B89D80D690E79A1C0B941430F ] xusb21          C:\Windows\system32\DRIVERS\xusb21.sys
13:52:28.0467 0x1468  xusb21 - ok
13:52:28.0530 0x1468  [ A8A49F0427D783BFF78BC3226B4ABD0D, BE074147C825292C5A4CB859EE0238061511753F24348975BC51B313F370DD2C ] ZAPrivacyService C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
13:52:28.0545 0x1468  ZAPrivacyService - ok
13:52:28.0686 0x1468  [ A0E02EE5D259CBC2A0844E9AEB5DC9DD, F3FC69545E48407AEA01D8F1443C3D6F2FDEAF5683B4B319ABDDD1B03983B58E ] ZoneAlarm AntiTheft C:\Program Files\CheckPoint\AntiTheft\Antitheft.exe
13:52:28.0732 0x1468  ZoneAlarm AntiTheft - ok
13:52:28.0810 0x1468  [ 3CB263CF60B253BEAD6E0205E1FA5669, 2BE90700FBB6DACBAE600065F1F364828DC91036F9A7EAB5156B9BDC6DF398A9 ] {329F96B6-DF1E-4328-BFDA-39EA953C1312} C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl
13:52:28.0826 0x1468  {329F96B6-DF1E-4328-BFDA-39EA953C1312} - ok
13:52:28.0857 0x1468  ================ Scan global ===============================
13:52:28.0888 0x1468  [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
13:52:28.0920 0x1468  [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
13:52:28.0935 0x1468  [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
13:52:28.0966 0x1468  [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
13:52:28.0998 0x1468  [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
13:52:28.0998 0x1468  [ Global ] - ok


Friedrich_ 28.03.2015 14:57

re 7.2
 
TDSKiller-LOG: Teil 2
Code:

13:52:28.0998 0x1468  ================ Scan MBR ==================================
13:52:28.0998 0x1468  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:52:29.0122 0x1468  \Device\Harddisk0\DR0 - ok
13:52:29.0138 0x1468  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
13:52:29.0341 0x1468  \Device\Harddisk1\DR1 - ok
13:52:29.0341 0x1468  [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk3\DR3
13:52:29.0873 0x1468  \Device\Harddisk3\DR3 - ok
13:52:29.0873 0x1468  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR2
13:52:30.0248 0x1468  \Device\Harddisk2\DR2 - ok
13:52:30.0248 0x1468  ================ Scan VBR ==================================
13:52:30.0248 0x1468  [ 2304D6384339F03F022DDB0DABA41E42 ] \Device\Harddisk0\DR0\Partition1
13:52:30.0279 0x1468  \Device\Harddisk0\DR0\Partition1 - ok
13:52:30.0294 0x1468  [ B3F6234387526643305E8FB300708F0C ] \Device\Harddisk1\DR1\Partition1
13:52:30.0357 0x1468  \Device\Harddisk1\DR1\Partition1 - ok
13:52:30.0357 0x1468  [ 9C0228DE540D2D235A548B2A40644D90 ] \Device\Harddisk3\DR3\Partition1
13:52:30.0450 0x1468  \Device\Harddisk3\DR3\Partition1 - ok
13:52:30.0450 0x1468  [ 89EE3C2FD4D144EF6F7FE36D5DE95218 ] \Device\Harddisk2\DR2\Partition1
13:52:30.0513 0x1468  \Device\Harddisk2\DR2\Partition1 - ok
13:52:30.0513 0x1468  [ 234F1DDB7B0FD306282AB036208E4D3E ] \Device\Harddisk2\DR2\Partition2
13:52:30.0575 0x1468  \Device\Harddisk2\DR2\Partition2 - ok
13:52:30.0575 0x1468  ================ Scan generic autorun ======================
13:52:30.0622 0x1468  [ 0C944B589C7959F4F271F833D8B1489A, BB15DEDE6C8C280B7A4C14FD03C5BB9B040FEFFE0F06830B126952CF265E1FE9 ] C:\Program Files\Virtual CD v10\System\VC10Play.exe
13:52:30.0638 0x1468  VC10Player - ok
13:52:30.0669 0x1468  [ 796227FCA947A0B8E3D6A097B27F2363, F14B1F8CF253A27554D4C24228911355FA475AABF086B66A498E825E8E3CBFA5 ] C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
13:52:30.0669 0x1468  USB3MON - ok
13:52:30.0716 0x1468  [ 1B4F1E30129D8F511CCF35002D3BC43D, 5F6DB243387B4775BFEF74C8D8AEA25F8E82F3462CE294555FD0281587EE430B ] C:\Program Files\CheckPoint\AKL\AkSA.exe
13:52:30.0747 0x1468  ISW - ok
13:52:30.0825 0x1468  [ DD15D9965943525DB892296B3DE6E263, 17ACDA449D284DDDA27BF30E5055F549DEFDAEBB8F05E4D13F199CE7886F6846 ] C:\Program Files\Microsoft LifeCam\LifeExp.exe
13:52:30.0840 0x1468  LifeCam - ok
13:52:30.0950 0x1468  [ D468102B308978A0D60E11E8E120FDC8, F52CD70AC28F42299820218FFA633570B9741B3960486486176E9EDDE176690E ] C:\Program Files\Razer\Synapse\RzSynapse.exe
13:52:30.0981 0x1468  Razer Synapse - ok
13:52:30.0996 0x1468  [ 9D197E4D8D7ED5302609808CD21D56C0, E8343971C9E5141C9A26E552063666BB3AA1067FD7E7F9462976D07F1D9D5DE1 ] C:\Program Files\Logitech\Gaming Software\LWEMon.exe
13:52:31.0012 0x1468  Start WingMan Profiler - ok
13:52:31.0106 0x1468  [ 3D9405DC4F26BF0FE6138AE8DC2D4F9F, F6348C4FE965F6BC1A04ACB187B2600B5DE19E5C497BDAFB4A0C4B1B5B486CD3 ] C:\Program Files\Kalenderchen\Kalenderchen.exe
13:52:31.0171 0x1468  DMS-Kalenderchen - detected UnsignedFile.Multi.Generic ( 1 )
13:52:31.0770 0x1468  Detect skipped due to KSN trusted
13:52:31.0770 0x1468  DMS-Kalenderchen - ok
13:52:31.0770 0x1468  Waiting for KSN requests completion. In queue: 166
13:52:32.0848 0x1468  AV detected via SS2: ZoneAlarm Extreme Security Antivirus, C:\Program Files\CheckPoint\ZoneAlarm\\MultiFix.exe ( 13.2.15.0 ), 0x40000 ( disabled : updated )
13:52:32.0848 0x1468  FW detected via SS2: ZoneAlarm Extreme Security Firewall, C:\Program Files\CheckPoint\ZoneAlarm\\MultiFix.exe ( 13.2.15.0 ), 0x40010 ( disabled )
13:52:32.0848 0x1468  Win FW state via NFP2: enabled
13:52:33.0379 0x1468  ============================================================
13:52:33.0379 0x1468  Scan finished
13:52:33.0379 0x1468  ============================================================
13:52:33.0379 0x1460  Detected object count: 1
13:52:33.0379 0x1460  Actual detected object count: 1
13:53:07.0003 0x1460  nlsvc ( UnsignedFile.Multi.Generic ) - skipped by user
13:53:07.0003 0x1460  nlsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip


schrauber 28.03.2015 21:58

Benutzt Du irgend ne Disk-Verschlüsselung? Daher kann der Forged EIntrag kommen.

Lade dir bitte Emsisoft MBR Master herunter und speichere es auf den Desktop.
  • Führe die mbrmastr.exe aus.
  • Drücke auf Backup MBR und speichere es als emsi auf den Desktop.
  • Schliesse dann das Programm wieder.
  • Packe die erstellte emsi.mbr in ein zip-Archiv (Rechtsklick -> Senden an -> Zip-komprimierten Ordner) und hänge die Datei hier an.
  • Auf dem Desktop wird ebenfalls eine Textdatei MBRMastr_<date>_<time>.txt erstellt. Poste deren Inhalt bitte hier.

Friedrich_ 29.03.2015 09:57

re8
 
Liste der Anhänge anzeigen (Anzahl: 1)
Moin Schrauber,

Damit wir im System rumwerkeln können, habe ich nun alle festplatten bis auf
meine zwei 3TB hd's vom mainboard abgesteckt, und mit Acronis 2014(BootCD) Laufwerk C:
auf die andere festplatte geklont.
Die Hauptfestplatte bezeichnen wir als WD Black, das geklonte System als WD Red.
Da es kein GPT ist, werden logischerweise nur jeweils 2TB von win erkannt. der rest ist jeweils 'unalloziiert'.

Nun habe ich die WD Black mal abgesteckt, und das geklonte system auf der WD Red gestartet.
JEtzt wird es spannend, dort nämlich passieren die seltsamen Verbindungsaufrufe nicht!!
Formatiere ich jetzt die WD Black(hauptfestplatte) und klone von der WD Red das system auf die WD Black zurück, spielt die svchost wieder eigenleben (auf der WD Black).

Also vermute ich das entweder die spyware nur auf den Vendor/DeviceID reagiert, der bootmanger oder bootsector
irgendwie befallen ist, oder evtl was im 'unalloziierten bereich' liegt. Eine Verschlüsselung wurde nicht eingesetzt.


Hier ein Screenshot von dem geklonten system das knapp 40 min. läuft ohne svchost-verhalten, im Anhang:


PS: Wir können uns also auf Laufwerk C: austoben.:pirat:

MBR -LOG. FZEX = WD Black, EFRX = WD Red
Code:

Detected Windows version: 6.1 Build 7601 Service Pack 1
Installing direct disk access driver ...
Driver connection handle: 0x000000E0
2 valid drive(s) found.

Details for Disk 0 - WDC WD3003FZEX-00Z4SA0 Rev 01.01A01:
  Device name              : \\.\PhysicalDrive0
  Geometry (C/H/S)        : 364801/255/63
  Boot loader reputation  : Known Good (Windows 7)
  Cross view comparison    : Passed
  Partition table integrity: Passed

  Boot loader hashes
    SHA-1                  : 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
    MD5                    : A36C5E4F47E84449FF07ED3517B43A31


Details for Disk 1 - WDC WD30EFRX-68EUZN0 Rev 80.00A80:
  Device name              : \\.\PhysicalDrive1
  Geometry (C/H/S)        : 364801/255/63
  Boot loader reputation  : Known Good (Windows 7)
  Cross view comparison    : Passed
  Partition table integrity: Passed

  Boot loader hashes
    SHA-1                  : 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
    MD5                    : A36C5E4F47E84449FF07ED3517B43A31


schrauber 29.03.2015 16:26

Was sagt denn MBAR jetzt zu beiden Platten?

Friedrich_ 30.03.2015 05:53

re9
 
Malwarebytes Anti Rootkit-LOG: WD Black
Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2015.03.30.01

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.17691
Friedrich :: DSLSERVICE [administrator]

30.03.2015 05:44:15
mbar-log-2015-03-30 (05-44-15).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged.
Objects scanned: 453635
Time elapsed: 47 minute(s), 28 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 4
Physical Sector #5860513168 on Drive #0 (Forged physical sector) -> No action taken.
Physical Sector #5860515472 on Drive #0 (Forged physical sector) -> No action taken.
Physical Sector #5860515508 on Drive #0 (Forged physical sector) -> No action taken.
Physical Sector #5860515544 on Drive #0 (Forged physical sector) -> No action taken.

(end)



Malwarebytes Anti Rootkit-LOG: WD Red
Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2015.03.30.01

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.17691
Friedrich :: DSLSERVICE [administrator]

30.03.2015 04:16:00
mbar-log-2015-03-30 (04-16-00).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged.
Objects scanned: 453550
Time elapsed: 52 minute(s), 13 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 1
Physical Sector #5860513168 on Drive #0 (Forged physical sector) -> No action taken.

(end)


schrauber 30.03.2015 17:15

Bei Black mal löschen.

Friedrich_ 30.03.2015 19:35

re10
 
Grüß dich Schrauber,

Du wirst es nicht glauben, aber Tatsächlich war die malware (welche auch immer) in den "Forged physical sector" versteckt. Die verbindungsaufrufe finden nun nichtmehr statt!
pff wer hätte das gedacht, bin erstaunt.

Zwar sind nach neustart die Forged physical sector's wieder da, jedoch kein Malwareauftreten mehr zu beobachten. Genial. aber wie kann das sein. Was sind diese 'vergessenen sectoren' ??!?

Malwarebytes Anti Rootkit-LOG:
Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2015.03.30.06

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.17691
Friedrich :: DSLSERVICE [administrator]

30.03.2015 18:44:48
mbar-log-2015-03-30 (18-44-48).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged.
Objects scanned: 452982
Time elapsed: 44 minute(s), 6 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 4
Physical Sector #5860513168 on Drive #0 (Forged physical sector) -> Replace on reboot.
Physical Sector #5860515472 on Drive #0 (Forged physical sector) -> Replace on reboot.
Physical Sector #5860515508 on Drive #0 (Forged physical sector) -> Replace on reboot.
Physical Sector #5860515544 on Drive #0 (Forged physical sector) -> Replace on reboot.

(end)


Nach dem neustart hab ich nochmal gescannt, die sektoren sind wieder da aber die malware wohl hin und fort.

Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2015.03.30.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.17691
Friedrich :: DSLSERVICE [administrator]

30.03.2015 19:39:21
mbar-log-2015-03-30 (19-39-21).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged.
Objects scanned: 129976
Time elapsed: 35 minute(s), 15 second(s) [aborted]

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 4
Physical Sector #5860513168 on Drive #0 (Forged physical sector) -> No action taken.
Physical Sector #5860515472 on Drive #0 (Forged physical sector) -> No action taken.
Physical Sector #5860515508 on Drive #0 (Forged physical sector) -> No action taken.
Physical Sector #5860515544 on Drive #0 (Forged physical sector) -> No action taken.

(end)


schrauber 31.03.2015 05:21

das heisst nicht vergessen, sondern gefälscht :)

Friedrich_ 06.04.2015 12:26

re10.1
 
Ach jaa, sorry Forged, ich las 'forget' *ditsch*.

Habe das jetzt über die Woche hin beobachtet und bisher ist alles soweit
clean. Damit können wir den Thread hier abschließen und ich bedanke mich nochmals
für deine tolle Unterstützung. Ohne die wir vermutlich nicht auf die Sektoren gestoßen wären.
Danke. mfg. Friedrich :dankeschoen:

schrauber 06.04.2015 17:49

http://deeprybka.trojaner-board.de/b...cleanupneu.png
Cleanup:
(Die Reihenfolge ist hier entscheidend)

Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken.

Falls Combofix verwendet wurde:
http://deeprybka.trojaner-board.de/b.../combofix2.pngCombofix deinstallieren
  • Wichtig: Bitte Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren.
  • Drücke bitte die http://deeprybka.trojaner-board.de/b...ne/revo/w7.png + R Taste und schreibe Combofix /Uninstall in das Ausführen-Fenster.
  • Klicke auf OK.
    Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert.
  • Nun die eben deaktivierten Programme wieder aktivieren.

Alle Logs gepostet? Dann lade Dir bitte http://filepony.de/icon/tiny/delfix.pngDelFix herunter.
  • Schließe alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Setze vor jede Funktion ein Häkchen.
  • Klicke auf Start.

Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen.

Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...:dankeschoen:und/oder das Forum mit einer kleinen Spende http://www.trojaner-board.de/extra/spende.png unterstützen. :applaus:

http://deeprybka.trojaner-board.de/b...ast/schild.png
Absicherung:
Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen:

Browser
Java
Flash-Player
PDF-Reader

Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren.
Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen.

Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig.

Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank.
Meine Empfehlung:
http://filepony.de/icon/emsisoft_anti_malware.png
Emsisoft

Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen.

Optional:
http://filepony.de/icon/noscript.png NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen.
http://filepony.de/icon/malwarebytes_anti_exploit.pngMalwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen.


Lade Software von einem sauberen Portal wie http://filepony.de/images/microbanner.gif.
Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen.
Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwcleaner .


Abschließend noch ein paar grundsätzliche Bemerkungen:
Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems.
Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.


Alle Zeitangaben in WEZ +1. Es ist jetzt 10:41 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131